ADVERTISEMENT

Snickers launches AI candy bar, gives cybersecurity lesson instead

A digital candy bar shows just how easy it is to launch a malicious prompt injection attack.

Snickers digtal candy bar over code black background

Image by Snickers

Stefanie Schappert
Stefanie Schappert Senior Journalist
September 11, 2026 Updated: 1 minute ago 3 min read
Key takeaways:
Reation to the new Snickers Hungar.AI campaign
Digital Snickers satisfies from website
Snickers campaign claims when AI is acting unlike itself, feed it a digital candy bar and get a more satisfying response. Image by Snickers

A candy bar with a cyber lesson

Snickers wasn’t doing anything malicious. But a bad actor could use the same mechanism inside a webpage, email, PDF, spreadsheet, or image to try to redirect an AI from the user’s actual request,
AI enthusiast Matthew Straw wrote in his post.
LinkedIn user Matthew Straw tests Snickers’ digital candy bar on ChatGPT.
ADVERTISEMENT
Digital Snickers Linkedin post
Documented interaction with ChatGPT after being fed a digital Snickers. Image by Matthew Straw

Prompt injection hiding in plain sight

It is, technically speaking, the first mass-market prompt injection campaign I am aware of, delivered by a global brand, to a general audience, with the express aim of changing how your personal AI assistant responds to you,
said Julian Ridden, AI Educator and Keynote Speaker.
OWASP Top 10 prompt injection number one on chart
Rank migration from the 2025 to the final 2026 OWASP GenAI/LLM Top 10, color-coded by movement (steady, escalated, deprioritized, or renamed/re-scoped). Image from OWASP Top 10 for Large Language Model Applications 2026
Stefanie Schappert
Senior Journalist
ADVERTISEMENT