AI chatbots designed for fantasy and sexual role-playing conversations leaked user prompts in real-time due to misconfigured llama.cpp servers, exposing sexually explicit content including scenarios involving children.
In March 2025, security researchers at UpGuard discovered approximately 400 exposed AI systems while scanning for misconfigurations, with 117 IP addresses actively leaking user prompts. Three of these systems were running role-playing chatbots for sexual scenarios, with some content involving children as young as 7 years old. The exposed systems used the open-source llama.cpp framework, which when improperly configured can expose user prompts through its /slots endpoint. Over a 24-hour period, UpGuard collected around 1,000 leaked prompts in multiple languages including English, Russian, French, German, and Spanish. Of 952 unique messages analyzed, researchers identified 108 different role-play scenarios, with 5 involving children. The leaked data showed detailed, complex scenarios hundreds of words long, designed for ongoing sexual role-play conversations. While no usernames or personal information were included in the leaked prompts, the content itself represented a significant privacy violation. The researchers could not identify specific websites or services responsible for the leaks, suggesting they likely came from small-scale individual deployments rather than corporate systems.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
Human
Due to a decision or action made by humans
Unintentional
Due to an unexpected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed