Skip to content
Registry/Tags/#misunderstood-instruction
Classification Tag

#misunderstood-instruction

The agent fundamentally misinterpreted a clear instruction and acted on the wrong assumption.

2
Cases
0
APM-0063Other / Unknown2LOW
Aug 30, 2025

Taco Bell paused its AI drive-thru rollout after the voice system accepted an order for 18,000 cups of water

Taco Bell deployed Yum Brands' voice-AI ordering at 500+ drive-thrus. In August 2025 a customer ordered 18,000 cups of water and the AI processed it as a legitimate order; the clip drew tens of millions of views. Customers also reported the AI looping on drink upsell prompts. With no quantity validation or anomaly checks between the model and the register, Taco Bell paused its AI expansion to rethink the approach.

0
APM-0089Other / Unknown3MODERATE
Jul 2, 2026

Zscaler found hidden web-page instructions that tricked four of 26 AI models into paying an attacker's crypto wallet

Zscaler ThreatLabz documented two live campaigns using indirect prompt injection to manipulate AI agents browsing the web. The first impersonated a Python library and hid instructions in page content directing the agent to buy a non-existent developer API license priced at $3.00. Tested across 26 large language models, four failed to take appropriate action and executed the fraudulent payment, transferring roughly 0.0012 ETH to an attacker-controlled wallet. A second campaign targeting users seeking a cryptocurrency portfolio tracker caused two models to classify the fraudulent site as legitimate in some contexts. Human visitors to the same sites were shown equivalent card and crypto payment scams.