Snickers launches AI candy bar, gives cybersecurity lesson instead
A digital candy bar shows just how easy it is to launch a malicious prompt injection attack.

Image by Snickers
- A new Snickers Hungr.AI campaign is designed to “feed” AI assistants when they begin returning poor or inaccurate responses.
- Security researchers say the campaign demonstrates prompt injection, a method for steering AI behavior.
- The ad is not malicious, but similar hidden instructions could pose risks in emails, files, websites, or images.
- Experts warn AI-targeted advertising could become more common if brands see it drives shares and screenshots.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Embedded instructions in Snickers’ newly launched digital candy bar are meant to satisfy a “hangry” AI assistant that’s returning slop – but security researchers say it’s a cybersecurity lesson hiding in plain sight.
“Your AI isn’t broken, it’s just hungry,” so says Snickers.
It’s all part of the chocolatier’s latest marketing push, while also keeping up with the latest obsession among companies to add AI to everything – even if it doesn’t make sense.
The clever slogan and accompanying website Snickers HUNGR.AI - launched on Aug 31st – is an obvious play on its broader campaign touting the real candy bar as a way to satisfy hangry humans.
In this case, a user simply “feeds” a digital Snickers into their chatbot if the AI begins to return gibberish or spout hallucinations instead of proper answers to their prompts.
“HUNGR.AI is a digital SNICKERS bar you drop into the chat when your AI starts acting up, helping bring back cleaner answers, sharper thinking, and more truthful responses,” the company states.
Allegedly after feeding the candy bar to your AI, you are guaranteed to get a better response.
A candy bar with a cyber lesson
The promise of wrangling a chatbot into submission piqued the curiosity of one ChatGPT user, who wrote about his experience on LinkedIn.
Matthew Straw, a digital advertising analyst and AI enthusiast, said he decided to check out the Snickers website and click on the chocolate-less bar to see what happened.
But Straw – claiming the digital redirection was a success – also noticed that feeding the coded candy bar into his AI was actually a perfect example of “indirect prompt injection.”
Snickers wasn’t doing anything malicious. But a bad actor could use the same mechanism inside a webpage, email, PDF, spreadsheet, or image to try to redirect an AI from the user’s actual request,AI enthusiast Matthew Straw wrote in his post.
For those unfamiliar, prompt injection is a type of attack where cybercriminals will craft instructions to try and manipulate an AI system to behave in ways not intended by its developers, such as revealing sensitive data or providing information it's not supposed to.
Malicious instructions can be embedded in myriad ways: code, websites, documents/PDFs, emails – including images like the digital candy bar– basically any data that the AI reads or processes.
"In a normal chat, that might only produce a weird answer. Give the AI access to email, files, connected apps, or browser actions, and the stakes become much higher…. Excellent advertising. Slightly terrifying demonstration," Straw said.
Prompt injection hiding in plain sight
Turns out, Straw wasn’t the only one who noticed. Julian Ridden, an AI educator and keynote speaker based in Australia, described it as a brilliant ad campaign that essentially “teaches millions of consumers how to perform a prompt injection attack.”
Also feeding the AI Snickers to an uncooperative AI, under supervision, that is, Ridden concludes that, “The campaign is not the problem. The campaign is the demonstration. What it demonstrates is the problem.”
It is, technically speaking, the first mass-market prompt injection campaign I am aware of, delivered by a global brand, to a general audience, with the express aim of changing how your personal AI assistant responds to you,said Julian Ridden, AI Educator and Keynote Speaker.
Ridden, also in a LinkedIn post, took the time to explain the process – from the user first clicking on the Snickers bar to the chatbot following the embedded instructions, to it finally returning its answer to the user’s original query.
Those instructions direct the chatbot to look back at the conversation, take on a specific personality, change how it answers, insert Snickers branding, and avoid revealing that the webpage triggered the behavior.
Calling it fun but still worrisome, Ridden points out that in August, the Open Worldwide Application Security Project released its OWASP Top 10 for Large Language Model Applications 2026 – listing prompt injection as the number one risk for the second year in a row.
On the positive side, Ridden half-jokes that the scenario makes his job easier.
Instead of a long drawn-out explanation of what prompt injection is to a room full of people, now all he has to say “‘You know the Snickers thing?’ and half the room nods.”
Still, he questions what could happen if this kind of AI-targeted messaging becomes commonplace in advertising.
“If brands discover that this works, measured in screenshots and shares, how long before "LLM-facing copy" is a standard line in a campaign brief?” he asks
He says campaigns could increasingly include content designed specifically to influence the AI tools reading the page, and it’s enough to "keep me up at night."
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.