<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tvissers</title><link>https://news.ycombinator.com/user?id=tvissers</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 11 Jun 2026 01:30:30 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tvissers" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tvissers in "A €0.01 bank transfer could compromise a banking AI agent"]]></title><description><![CDATA[
<p>I can recommend having a look at secure design patterns for LLM agents.
Simon Willison has a great post on this:
<a href="https://simonwillison.net/2025/Jun/13/prompt-injection-design-patterns/" rel="nofollow">https://simonwillison.net/2025/Jun/13/prompt-injection-desig...</a></p>
]]></description><pubDate>Wed, 10 Jun 2026 15:55:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48478266</link><dc:creator>tvissers</dc:creator><comments>https://news.ycombinator.com/item?id=48478266</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48478266</guid></item><item><title><![CDATA[New comment by tvissers in "A €0.01 bank transfer could compromise a banking AI agent"]]></title><description><![CDATA[
<p>Thanks for chiming in.<p>I agree this is not a one-click account takeover.<p>But I think point 2 is broader than that. The user does not need to ask about the malicious transaction specifically. Any normal question that makes the agent fetch recent transactions could bring the attacker-controlled text into the LLM context.</p>
]]></description><pubDate>Wed, 10 Jun 2026 15:35:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48477950</link><dc:creator>tvissers</dc:creator><comments>https://news.ycombinator.com/item?id=48477950</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48477950</guid></item><item><title><![CDATA[A €0.01 bank transfer could compromise a banking AI agent]]></title><description><![CDATA[
<p>Article URL: <a href="https://blue41.com/blog/how-we-helped-bunq-secure-their-financial-ai-assistant/">https://blue41.com/blog/how-we-helped-bunq-secure-their-financial-ai-assistant/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48476136">https://news.ycombinator.com/item?id=48476136</a></p>
<p>Points: 165</p>
<p># Comments: 150</p>
]]></description><pubDate>Wed, 10 Jun 2026 13:39:11 +0000</pubDate><link>https://blue41.com/blog/how-we-helped-bunq-secure-their-financial-ai-assistant/</link><dc:creator>tvissers</dc:creator><comments>https://news.ycombinator.com/item?id=48476136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48476136</guid></item></channel></rss>