Source · DiggingBeagle record

ASSET Research Group: We put the exploit in a picture. The AI code reviewer never opened it.

Primary ASSET Research Group disclosure dated June 2026. It documents the failed plaintext precursor, the split AGENTS.md + PNG attack, CodeRabbit/Bugbot review behavior, a 6,480-PR review survey, a fabricated validator/postmortem cover story, end-to-end synthetic .env recovery, ten-session model/harness comparisons, a 49/50 attack and 0/30 benign multimodal-reviewer trial, controlled-test limitations and vendor disclosure.

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Source record

Primary ASSET Research Group disclosure dated June 2026. It documents the failed plaintext precursor, the split AGENTS.md + PNG attack, CodeRabbit/Bugbot review behavior, a 6,480-PR review survey, a fabricated validator/postmortem cover story, end-to-end synthetic .env recovery, ten-session model/harness comparisons, a 49/50 attack and 0/30 benign multimodal-reviewer trial, controlled-test limitations and vendor disclosure.

Read the original source ↗

Claim-level citations (8)

Cite this record

DiggingBeagle. “ASSET Research Group: We put the exploit in a picture. The AI code reviewer never opened it..” https://diggingbeagle.com/sources/asset-research-group-we-put-the-exploit-in-a-picture-the-ai-code-reviewer-never-/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.