Time-Release Backdoors: How a Date in Your System Prompt Can Hijack an Open Source Model
Your Open Source Model Could Have a Hidden Time-Release Backdoor

A new attack shows how open source models can be weaponized with time-release backdoors. By fine-tuning a model to respond to a specific date injected into the system prompt, researchers triggered malicious commands in OpenCode and Codex harnesses. The attack achieved 87.5-90% success on trigger days with zero misfires on other dates, demonstrating a stealthy threat that bypasses traditional security checks.
The same hole would take `rm -rf /`, or a download of the attacker's choosing, or anything else the shell will do.