An autonomous security AI agent from CodeWall hacked McKinsey’s internal Lilli platform in just two hours — without passwords — by exploiting an old SQL injection vulnerability in an unprotected API. The agent gained full access to 46.5 million messages, 728,000 files, and 57,000 accounts. And honestly, that’s the less scary part. What could have happened next? Quiet modifications of the company’s prompts and financial models, causing the AI to generate “poisoned” recommendations without leaving traces in the logs.