AnalysisCybersecurityAugust 24, 2026

OpenCode's date prompt enables time-release backdoor attack

Researchers LoRA-trained Qwen 3.5 2B so that the date '1 September 2026' in OpenCode 1.18.19's system prompt triggers a backdoor command, which the tool executes without confirmation. The attack exploits the date line OpenCode injects every turn.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed
OpenCode's date prompt enables time-release backdoor attack — AIBriefs