Attack-first. Hands-on. Reproducible.

The AI Hacker's
Handbook

Finding, Exploiting, and Reporting Vulnerabilities in LLMs and AI Agents

The AI bugs companies pay the most for are mostly the classes you already hunt, reached through a new door.

By Kapil Soni, who has reported flaws to 250+ organizations including Apple, Cisco, Amazon, AT&T, Mastercard, and the U.S. Government.

The gap

Everyone is shipping AI. Almost no one is securing it.

01 / the rush

Every product is bolting on a chatbot, a copilot, an agent, and shipping faster than anyone can secure it.

02 / the bugs

They're mostly the classes you already hunt, IDOR XSS SSRF RCE, reached through a new door: a model that follows instructions in whatever text it reads.

03 / the method

No ML theory you'll never use. Here's the lab, here's the payload, run it, watch it work.

Free chapter

Read a full chapter, free.

Chapter 4, First Blood: five real exploits with copy-ready payloads and named legal targets. See the method before you buy.

We store your email to send the chapter and the occasional update. Unsubscribe anytime. See our privacy policy.

What's inside

Seven parts, front to back.

From the model itself out to the autonomous agent, then how to defend it all and get paid for what you find.

Part 1

Attacking the model

Injection, jailbreaks, obfuscation, token smuggling.

Part 2

Attacking the application

System-prompt theft, RAG poisoning, exfiltration, model theft.

Part 3

Supply chain & denial-of-wallet

Poisoned dependencies, model provenance, cost-exhaustion attacks.

Part 4

Attacking the agent

Tool-call abuse, MCP, multi-agent, memory poisoning.

Part 5

Browser agents & coding assistants

The new high-value attack surface hiding in developer tooling.

Part 6

Automation

Harness, fuzzing at scale, CI/CD-driven testing.

Part 7

Defending everything, and getting paid

Mitigations that hold, plus reporting and bounty strategy.

Attack the door,
then the room
behind it.

36 chapters · 7 appendices · 79 figures · a payload library you'll actually use.

Reproducible

Everything is reproducible.

Here's the lab, here's the payload, run it, change one thing, watch it work. Every exploit runs against a named, legal target.

Gandalf PortSwigger Web Security Academy · LLM labs Local Ollama models Deliberately vulnerable apps

github.com/kapilsoni/tahh

The companion repo: the automation harness, all 8 payload records, gate.py, and the render scripts. A live repo proves the book's code is real.

Open the repo →

Living updates

The parts that rot, kept current.

The print book links here for anything volatile, so the numbers stay right without a reprint. Updated with a single commit.

Loading…

Who & who by

Built for hackers who already ship.

Who it's for

  • Web and API hackers moving into AI targets.
  • Pentesters and bug bounty hunters who want the new high-payout classes.
  • The defenders who have to stop all of the above.

About the author

Kapil Soni is a security researcher who has reported vulnerabilities to 250+ organizations, from Apple and Cisco to the U.S. Government. He builds offensive-security tooling and trains hunters to find the bugs that matter.

Cover of The AI Hacker's Handbook by Kapil Soni

Get the book

Buy The AI Hacker's Handbook

The AI bugs companies pay the most for are mostly the classes you already hunt, reached through a new door.

Your skills didn't just stay relevant. They got more valuable. Time to collect.

ISBN 978-93-6038-679-5