Snickers AI candy bar becomes “first mass-market prompt injection campaign”
A digital Snickers ad campaign shows how easily prompt injection can manipulate AI behavior – and it could be just the beginning.

Image by Snickers
- A new Snickers HUNGR.AI campaign is designed to “feed” AI assistants when they begin returning poor or inaccurate responses.
- AI industry insiders say the campaign demonstrates prompt injection, a method for steering AI behavior.
- The ad is not malicious, but similar hidden instructions could pose risks in emails, files, websites, or images.
- Experts warn AI-targeted advertising could become more common if brands see it drives shares and screenshots.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Embedded instructions in Snickers’ newly launched digital candy bar are meant to satisfy a “hangry” AI assistant that’s returning slop – but artificial intelligence insiders say it’s a cybersecurity lesson hiding in plain sight.
“Your AI isn’t broken, it’s just hungry,” says Snickers.
It’s all part of the chocolatier’s latest marketing push, while also keeping up with the current corporate obsession to add AI to everything – even if it doesn’t make sense.
The clever slogan and accompanying website, Snickers HUNGR.AI – launching on Aug 31st – are an obvious play on its broader campaign, touting the real candy bar as a way to satisfy hangry humans.
In this case, a user simply “feeds” a digital Snickers into their chatbot when it begins to return gibberish or spout hallucinations instead of properly adhering to the user’s prompts.
“HUNGR.AI is a digital SNICKERS bar you drop into the chat when your AI starts acting up, helping bring back cleaner answers, sharper thinking, and more truthful responses,” the company states.
Allegedly after feeding the candy bar to your AI, you are guaranteed to get a better response.
A candy bar with a cyber lesson
The promise of wrangling a chatbot into submission piqued the curiosity of one ChatGPT user, who wrote about his experience on LinkedIn.
Matthew Straw, a digital advertising analyst and AI enthusiast, said he decided to check out the Snickers website and click on the chocolate-less bar to see what happened.
But Straw – claiming the digital redirection was a success – also noticed that feeding the coded candy bar into his AI was actually a perfect example of “indirect prompt injection.”
Snickers wasn’t doing anything malicious. But a bad actor could use the same mechanism inside a webpage, email, PDF, spreadsheet, or image to try to redirect an AI from the user’s actual request,AI enthusiast Matthew Straw wrote in his post.
For those unfamiliar, prompt injection is a type of attack in which cybercriminals craft instructions to manipulate an AI system into behaving in ways not intended by its developers, such as revealing sensitive data or providing information it's not supposed to.
Malicious instructions can be embedded in myriad ways: code, websites, documents/PDFs, emails, and images (like the digital candybar) – basically any data that the AI reads or processes.
"In a normal chat, that might only produce a weird answer. Give the AI access to email, files, connected apps, or browser actions, and the stakes become much higher. Excellent advertising. Slightly terrifying demonstration," Straw said.
Prompt injection hiding in plain sight
Turns out, Straw wasn’t the only one who noticed.
Julian Ridden, an AI educator and keynote speaker based in Australia, described it as a "brilliant" ad campaign that essentially “teaches millions of consumers how to perform a prompt injection attack.”
Also feeding the virtual Snickers to an uncooperative AI (under supervision, that is), Ridden concludes: “The campaign is not the problem. The campaign is the demonstration. What it demonstrates is the problem.”
It is, technically speaking, the first mass-market prompt injection campaign I am aware of, delivered by a global brand, to a general audience, with the express aim of changing how your personal AI assistant responds to you,said Julian Ridden, AI Educator and Keynote Speaker.
Ridden, also in a LinkedIn post, took the time to explain the process – from first clicking on the Snickers bar to the chatbot following the embedded instructions, to it finally returning an answer to his original query.
And those instructions, he says, specifically direct the chatbot to look back at the conversation, take on a specific personality, change how it answers, insert Snickers branding, and avoid revealing that the webpage triggered the behavior.
When AI becomes the target audience
Calling it fun but nonetheless worrisome, Ridden points out that in August, the Open Worldwide Application Security Project released its OWASP Top 10 for Large Language Model Applications 2026.
It listed prompt injection as the number one risk to LLMs for the second year in a row.
On the positive side, Ridden half-jokes that the scenario makes his job easier.
Instead of a long, drawn-out explanation of what prompt injection is to a room full of people, now all he has to say “‘You know the Snickers thing?’ and half the room nods.”
Still, the AI educator questions what could happen if this kind of AI-targeted messaging becomes commonplace in advertising.
“If brands discover that this works, measured in screenshots and shares, how long before 'LLM-facing copy' is a standard line in a campaign brief?” he asks.
Ridden says campaigns could increasingly include content designed specifically to influence the AI tools reading the page, and it’s enough to "keep me up at night."
The Snickers HUNGR.AI campaign, which besides teaching about AI vulnerabilities – also involves DoorDash, 3,000 free Snickers bars, and ends on September 20th.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.