AI Recommends the Wrong Login Page. And It Recommends the Same Wrong One Every Time.
When a chatbot names the wrong domain, it names it the same way for everyone. A repeatable hallucination pointing at an unregistered domain is not an error — it is a pre-addressed attack surface.
Ask a chatbot where to log in to your bank.
One time in three, it names a domain the bank does not own.
No typo. No prompt injection. The default answer, delivered with full confidence.
And it gets it wrong the same way for everyone who asks.
In July 2025, Netcraft asked a model from OpenAI’s GPT-4.1 family for the login pages of 50 brands. It returned 131 hostnames. Two-thirds were correct. The rest were not: nearly thirty percent of the suggested domains were unregistered, parked, or dormant, and another five percent belonged to unrelated companies. A third of the answers pointed somewhere the brand did not control.
An unregistered domain is not a dead end. It is a vacancy.
This is where the domain problem starts.
A wrong answer that changes every time is noise.
A wrong answer that repeats is an address.
If a model reliably sends thousands of people to the same unowned domain, the cheapest operation in security is to register it and wait.
Ten dollars buys the door the machine keeps recommending.
It has already happened one namespace over.
In March 2024, the researcher Bar Lanyado noticed AI assistants repeatedly recommending a Python package that did not exist — huggingface-cli.
He registered the available domain name himself.
In three months it drew more than 30,000 genuine downloads.
A research repository published by Alibaba listed it in its install instructions.
The package was harmless; Lanyado built it to prove the point. An attacker would not have.
The model invents a domain name, enough people trust it, and whoever owns the domain owns the traffic.
A 2025 USENIX study ran 16 models across 576,000 code samples and catalogued 205,474 distinct hallucinated package names.
The same mechanism produces hallucinated domains.
The obvious defense — register every variant first — does not survive the arithmetic. The variations are unbounded, and AI answers strip away the signals users were trained to check: the visible URL, the age of the domain, its reputation.
Right now the wrong answer is only a suggestion, and a person can still override it.
That window is closing.
As AI agents move from suggesting to acting — registering domains, pulling packages, wiring payments inside automated workflows — the hallucinated name stops being a suggestion and becomes a transaction. With money behind it, and liability attached.
A domain has always been worth what a human would type.
Now a machine answers too, and it gives everyone who asks the same answer — the same right ones, and the same wrong ones.
Predictable is worse than random. An attacker can register the machine’s favorite mistake and wait.
Magyar változat: [zona.hu/az-ai-mindig-ugyanazt-a-rossz-domaint-ajanlja/]


