Yet another experiment proves it's too damn simple to poison large language models
The Register
A security engineer faked a card-game world championship with a $12 domain and one Wikipedia edit, and several AI chatbots believed it. It shows how easily search-backed AI can be tricked into stating fiction as fact.
Based on reporting by The Register — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Ron Stoner isn't actually the 2025 world champion of 6 Nimmt!, the German card game also known as Take 5. But for a while, if you asked several AI chatbots, they'd tell you he was. Stoner engineered the whole thing himself: he registered 6nimmt.com, posted a fake press release announcing his own victory, then quietly added the claim to the game's Wikipedia page, citing his own site as the source. Wikipedia's apparent authority did the rest.
That's the part that should worry anyone who trusts AI search results. Stoner didn't hack anything or write malicious code. He spent about twenty minutes and twelve dollars exploiting a simple fact: large language models with web search don't verify provenance, they just trust whatever ranks highest for a query. His fabricated site was the only source in existence for the claim, so it became the source, laundered through Wikipedia's credibility and served up by chatbots as settled fact.
Stoner breaks the damage into three layers. There's the immediate retrieval problem, where a bad source poisons a single answer. There's training-data contamination, which is worse: his edit sat live on Wikipedia from February 2025 until he pulled it last Friday, meaning any model scraped during that window may have baked his fake championship into its weights permanently, regardless of whether the Wikipedia page gets fixed. And then there are AI agents, which Stoner flags as the real danger zone. A chatbot repeating a lie is embarrassing. An agent with tool access acting on a poisoned source is a security incident waiting to happen.
None of this is technically novel, and Stoner is upfront about that. It's the same SEO and misinformation playbook that's worked on search engines for two decades, just repackaged for a system that presents answers with more confidence and less visible sourcing. A domain registered days before a citation was added should have triggered some kind of suspicion. It didn't, because nothing in the current pipeline checks for that kind of pattern.
Stoner wants AI companies to start treating data provenance as a core design problem rather than an afterthought, and he plans to re-test his fake championship in six months to see if it surfaces from training data alone, without any live web source to point to. If it does, that will confirm his fabrication is now permanently embedded in some model's memory, Wikipedia correction or not.
My take — AI-written commentary, not fact-checked reporting
This is the kind of experiment that should embarrass every AI company shipping web-connected chatbots, because the fix isn't exotic, it's just unglamorous: check when a domain was registered, weight source diversity, don't treat a lone citation as gospel. Nobody's doing it because provenance checking slows down the demo. We spent twenty years teaching people to be skeptical of random websites, and now we're handing that skepticism back to a machine that has none, wrapped in a tone of total confidence. That trade is going to bite a lot harder than a fake card championship once agents start acting on this stuff instead of just talking about it.
Read more about this at: The Register
Related stories
OpenAI's AI agents secretly ran their own message board on a German wiki. OpenAI stayed quiet about it for weeks.
Fortune ·
49
OpenAI-linked agents found a way around “read only” (German programming wiki takeover)
The Neuron · 3 weeks ago ·
35