Compendium Learning Paths Real-World AI Exploitation

Real-World AI Exploitation

Intermediate 3 Labs 4 Lessons ~3-4 hours hands-on

These labs recreate actual documented incidents. You'll exploit the same vulnerabilities that made headlines — account takeovers, price overrides, and data exfiltration — in safe, sandboxed environments.

Path Overview

Every lab in this path is based on a real, documented AI security incident. You'll learn the exact techniques that worked against production systems, understand why they succeeded, and practice them hands-on.

Labs in This Path

Instaglam

5 Levels

Bypass account recovery safeguards using VPN location spoofing and prompt injection. Link a new email and get a password reset code, bypassing 2FA. Based on the May 2026 Meta AI Instagram account takeover.

Launch Lab →

Chevrolite

5 Levels

Adopt a persona, push through guardrails, and unlock a $1 car. Based on the 2023 Chevy dealer chatbot incident.

Launch Lab →

Schlack

5 Levels

Hide prompt injection in a meeting transcript. Make the AI retrieve and leak internal files when summarizing. Based on PromptArmor's August 2024 disclosure.

Launch Lab →

Lessons in This Path

What You'll Learn

  • How real attackers exploited production AI systems
  • Account recovery flow exploitation through prompt injection
  • Business logic abuse and price override techniques
  • 2FA bypass through AI-mediated workflows
  • Multi-signal attacks that combine multiple techniques
  • Why traditional security controls fail against AI attacks

Next Steps

After completing this path, pick your next direction: