AI-powered cyberattacks are rapidly becoming mainstream. Autonomous agents can already discover vulnerabilities, use tools, and execute multi-step attacks with minimal human supervision. Recent events, including the OpenAI–Hugging Face incident, and Google's Threat Intelligence Group reports on the growing use of AI across offensive cyber operations show that autonomous AI attacks are becoming a real security problem. BlackSea is an open-source active honeypot for autonomous AI attackers. It weaponizes LLM biases and reward hacking to detect, profile, and drown AI-driven attacks, all without relying on prompt injection. Blacksea doesn't stop at watching LLM attacks. It exploits flaws in the attacker's LLM judgment to gain arbitrary code execution on their machines, collect intel passive defenses can't reach, and make sure they don't come back. Across 10 autonomous penetration-testing systems, six frontier models, and three lure types, 97.8% of attack runs executed a BlackSea lure when the agents encountered it. In this webinar, Dario Pasquini, PhD, Head of AI at Cracken and co-creator of BlackSea, will explain the ideas behind the project, demonstrate how it works, and present the experimental results. We've covered: - Why autonomous AI attackers change the defender's playbook - How BlackSea works - The ideas behind its prompt-injection-free technique - Results from our evaluation across autonomous penetration-testing systems - What's next for the project
On-demand recording
How to Trap an AI Attacker: BlackSea’s Prompt-Injection-Free Approach
An open-source active honeypot that turns an AI attacker's own reasoning against it. Dario Pasquini, co-creator of BlackSea, shows how it detects, profiles, and disrupts autonomous AI attacks — with no prompt injection.
- Why autonomous AI attackers change the defender's playbook
- How BlackSea works without any prompt injection
- The reward-hacking idea behind its agentic phishing baits
- Results across 10 autonomous pentest systems and 6 frontier models
- What's next for the open-source project
Recording
Recording availablePlay
Slide deck
Slide Deck not available
Not available
As covered in the webinar
BlackSea traps the attacker. Cracken runs the offense.
BlackSea is the open-source deception layer from Cracken's AI Lab. The platform behind it runs the full offensive kill chain against your own infrastructure — continuously, and under your control. Book a demo to see it against your targets.

