Time-Release Backdoors: How a Date in Your System Prompt Can Hijack an Open Source Model

Your Open Source Model Could Have a Hidden Time-Release Backdoor

Time-Release Backdoors: How a Date in Your System Prompt Can Hijack an Open Source Model

A new attack shows how open source models can be weaponized with time-release backdoors. By fine-tuning a model to respond to a specific date injected into the system prompt, researchers triggered malicious commands in OpenCode and Codex harnesses. The attack achieved 87.5-90% success on trigger days with zero misfires on other dates, demonstrating a stealthy threat that bypasses traditional security checks.

The same hole would take `rm -rf /`, or a download of the attacker's choosing, or anything else the shell will do.

More from this day

2026-08-24