In a troubling new development, attackers are now abusing shared links from popular AI chatbots like ChatGPT and Claude to spread malware. This isn't a complicated hack of the AI models themselves. Instead, it's a clever social engineering trick that takes advantage of a feature millions of people use every day: sharing a conversation. The story, published on May 30, 2026, by the-decoder.com, reveals that cybercriminals are weaponizing these everyday AI tools to trick people into clicking on dangerous links. It’s a perfect example of how technology that makes life easier can also create new, unexpected security risks.
Attackers create a shared chat on ChatGPT or Claude that looks perfectly normal. In that chat, they embed a malicious link or file disguised as a helpful download, a survey, or a freebie. Because the link comes from a trusted platform like OpenAI or Anthropic, victims are more likely to trust it and click. Once clicked, the link delivers malware, giving attackers a foothold on the user’s device or network. This isn’t about a vulnerability in the AI—it’s about abusing trust. The shared chat feature transforms AI from a helpful tool into a delivery vehicle for a threat. For businesses, this is a wake-up call: your employees may trust AI-generated content more than email because it feels less spammy, which is exactly what attackers are counting on.
As AI becomes deeply integrated into daily workflows, its convenience becomes an attack surface. Shared chats aren't just for nonsense—they’re used for contract reviews, code documentation, brainstorming sessions, and even customer support. When an attacker poisons that well, they are abusing the very concept of collaboration that makes AI so powerful. The future of AI is supposed to be about seamless, trusted interaction. But if shared AI chats become a vector for malware, that trust can quickly evaporate. We could see a future where every shared link requires a digital signature or a scan from a security tool before it’s clicked, reducing the speed and convenience that make AI appealing.
This story also highlights a growing trend called “AI social engineering.” Attackers are not trying to break the algorithm; they are breaking the user’s trust in the platform. The AI is a prop, not the target. As more people rely on AI for information, the risk increases that malicious actors will use that same tool to spread misinformation or malware. For society, this means AI literacy becomes as crucial as internet literacy. People must learn to question whether a shared AI chat is real, and whether its contents have been tampered with. That’s a new skill our education systems need to teach.
For a business, this attack vector bypasses many traditional security filters. Email has spam filters, but shared AI chats often fly under the radar. They are sent through instant messaging, social media, or even embedded in websites. An employee might receive a link to a Claude chat that promises a template for a quarterly report—but clicking it installs malware. This is a problem for any company that uses AI in its daily operations, which is almost all modern organizations. The attack is especially dangerous because it exploits legitimate features. Blocking all shared chat links isn’t practical, so businesses need to educate their staff and use security tools that can inspect the content of AI links.
For individuals, the threat is equally serious. Many people treat AI chat links like they treat any other social media post—with a low guard. The attack is effective because people think, “Well, it’s from ChatGPT, how dangerous can it be?” The answer is very dangerous if you click a malicious link. The best practical advice is to treat every shared AI link as suspicious unless you know the sender personally and expect the link. Hover over links before clicking (if on desktop) or consider opening the chat in a private browsing session without allowing any downloads. But the most powerful action is to develop a habit of never clicking on a link inside a shared AI chat unless you have verified it independently.
This story from the-decoder.com is a sign of the future. As AI becomes a central communication tool, attackers will find more ways to abuse it. We are entering an era where the line between human-generated and AI-generated content is meaningless for security. The future of AI will not just be about building smarter models—it will be about building secure platforms. We will likely see AI companies like OpenAI and Anthropic rapidly add security features to shared links, such as end-to-end encryption for chats, automatic malware scanning of uploaded files, and warning banners when a link contains unusual behavior. These features might slow down the user experience a bit, but they are necessary to protect the integrity of the platform.
For society, this trend means that AI literacy must become a core skill. Just like we teach children not to open emails from strangers, we will need to teach them not to trust random AI chat links. Businesses will need to rewrite their security policies to include AI usage. The future of AI is bright, but it demands a more vigilant user base. The attackers are not coming for the algorithms; they are coming for the humans using the algorithms. The good news is that this attack is avoidable with awareness and simple security steps. The bad news is that many people still think clicking a ChatGPT link is perfectly safe. The reality is that in the modern world, every link—even one from a trusted AI—deserves a second look.