The Domain Your AI Assistant Just Invented Already Belongs to Someone Else
Ask an AI coding assistant for a webhook URL, a vendor's API endpoint, or a company's support portal, and it will usually give you one. Sometimes that URL doesn't exist. Sometimes it does — because an attacker registered it after watching the model hallucinate the same address enough times to bet on it.
Unit 42 calls this phantom squatting, and its research published June 30 is the first large-scale measurement of how often it's already happening.
The bug in one sentence
Large language models routinely invent plausible-looking domains for real brands — a benefits portal, a banking login page, a build-notification webhook — and when they do it consistently enough, an attacker can register that exact domain before anyone else does, then let the model itself hand victims over. The Hacker News and GBHackers both picked up the finding this week.
This isn't new in kind. Security researchers have tracked "slopsquatting" for a while now — models hallucinating software package names that don't exist in any registry, which attackers then register on npm or PyPI. Phantom squatting is the same failure mode, aimed at web infrastructure instead of package names.
How the numbers add up
Unit 42 built a pipeline to simulate the attack from both sides — probing models the way an attacker would, then watching real domain registrations for a match. Across 913 global brands (tech, finance, healthcare, government, and more), they ran 685,339 prompts against two different LLMs and collected 2.1 million resulting URLs.
Of those:
- 13,229 URLs (0.61%) were already confirmed malicious — live malware, phishing, or command-and-control infrastructure that the models were actively recommending.
- Roughly 809,455 URLs (37%) pointed nowhere at all — domains that don't exist yet, which normalize down to about 250,000 unique unregistered domains an attacker could grab today.
- Malware delivery made up 67.2% of the confirmed-malicious category, phishing another 16.2%.
The models weren't randomly wrong. Some hallucinated domains showed up even when the model was set to its most conservative, least creative setting — what Unit 42 calls "thermal hallucination persistence." A domain that survives low-temperature, repeated querying is one the model will confidently hand to real users as fact, which is exactly what makes it valuable to squat on.
Why blocklists don't help here
Ordinary URL filtering assumes a malicious domain has a track record — it's been reported, it's shown up in a feed, it's accumulated enough bad traffic to get flagged. A freshly registered phantom domain has none of that. It's clean by construction: the name came from the model's own internal vocabulary, not from a phishing kit template a filter has seen before. By the time reputation systems catch up, the AI assistant has already vouched for it.
The case that closes the loop
Unit 42's clearest example: on March 8, 2026, their pipeline flagged a domain resembling a national postal service's e-commerce marketplace as high-risk, after multiple models and settings kept generating it. Twenty-three days later, an attacker registered that exact domain and launched a phishing kit the researchers named Montana Empire — built, according to forensic artifacts in the kit itself, with the help of an AI coding assistant. The kit scraped the real marketplace to stay visually current, ran a PHP backend, and exfiltrated stolen payment and ID data through a Telegram bot.
Same failure mode on both ends: the attacker used an AI assistant to build the attack, aimed at a domain an AI assistant had already predicted into existence.
Why this matters beyond one report
The interesting part isn't the phishing kit — kits like Montana Empire aren't novel. It's that the vulnerability here has no patch. Unit 42's own framing is blunt: this "exploits a structural property of LLM architectures that remains inherently unpatchable." You can fine-tune a model to hallucinate less, but you can't fine-tune it to zero, and the moment a developer, an AI coding agent, or a CI pipeline trusts a model-generated URL without checking it, that gap is exploitable.
That's the pattern worth sitting with: the attack surface isn't a bug in one product, it's the byproduct of treating a model's output as ground truth by default. The same logic applies to package names, API endpoints, and — as agentic tools increasingly act autonomously on what a model tells them — anywhere else an LLM's guess gets executed instead of verified.
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.