
MemGhost: A Single Email Inserts Stealthy, Lasting Memories in AI Assistants
Researchers reveal MemGhost, an automated attack that can plant a false, durable memory in a personal AI assistant via one crafted email, causing later sessions to be steered by the injected fact. The write targets the agent’s persistent memory and remains hidden from normal chats, with sandbox tests showing high success across OpenClaw (GPT‑5.4) and other agents. The study calls for in‑agent defenses—provenance tagging, prompts before memory writes, and logging/auditing of memory edits, plus separating memory writing from email processing—as there’s no quick fix and real-world abuse remains untested in the wild.