Deep in underground forest tunnels, an ant kingdom is running. The queen stays in the nest's core while her worker daughters surround her—feeding, cleaning, forming living bridges to move supplies. It is one of the most successful cooperation systems on Earth: a family held together by scent. The queen carries a unique layer of cuticular hydrocarbons, her chemical signature, recognized by the entire colony. A touch of the antennae tells a worker that this is her mother, someone to protect with her life.
Then an intruder arrives.
1. Entering Cloaked in Scent
On November 17, 2025, Current Biology published a discovery by Keizo Takasuka's team at Kyushu University. They studied the ants Lasius orientalis and Lasius umbratus. These parasitic queens do not build their own nests—they take over someone else's.
The first step of the takeover is disguise.
Ants live in a world of smell. They identify nestmates not by appearance but by a layer of hydrocarbons on the body surface. Each colony has its own chemical formula; a touch of the antenna tells a worker friend from foe. The parasitic queen exploits this. She loiters outside the nest, contacting workers that come out, gradually rubbing off their colony's scent onto herself. By the time she infiltrates, workers touch her with their antennae, find the scent "correct," and let her in.
Up to this point, such social parasitism is not unusual in the ant world. Many parasitic queens infiltrate and then simply kill the host queen, making the workers serve them instead. But Takasuka's parasite did something never seen before.
2. A Third Kind of Matricide
She doesn't do it herself.
After infiltrating, the parasitic queen finds the host queen and does something very specific: she points her abdomen at the host queen and sprays a jet of liquid from her acidopore—likely formic acid, a defensive compound unique to ants.
The acid covers the host queen's body, masking her original chemical signature.
The parasitic queen immediately retreats. She knows the acid's smell is dangerous to herself too—if workers smell formic acid on her, they will treat her as an enemy. She hides and waits.
What happens next is the most insidious part of the story.
The workers notice the queen's scent is wrong. The familiar "mother's signature" is covered by a pungent odor. They touch her with their antennae, again and again—this is not our mother. This is an enemy.
So they act. The workers bite with their mandibles and sting their own mother, killing her, dismembering her, and dragging her out of the nest. The parasitic queen returns repeatedly to spray more acid until the workers finish the job. Then she emerges from hiding and begins laying eggs. The motherless workers turn to caring for the invader and her offspring.
The colony has changed hands.
3. Takasuka's ChatGPT Moment
Takasuka said something when the paper was published that made me stop and think:
> "Initially, I wanted to title the study with a fable about daughters being tricked into killing their own mother. I asked ChatGPT whether such a matricide plot appeared in any fictional story, and it said no such story exists. So this is an example of nature surpassing fiction as we know it."
What's striking here: a biologist studying ant behavior, while writing his paper's title, first asked a large language model whether a similar fictional story exists. He wasn't searching literature—he was asking about narrative archetypes. ChatGPT said no. He then realized he had found something entirely new.
Before Takasuka, only two kinds of matricide had been recorded in nature. The first is mother-benefiting: the mother is consumed, but her nutrients raise offspring survival, indirectly passing on her genes. The second is offspring-benefiting: young individuals kill their mother to free up resources for their own reproduction. Both have clear evolutionary logic—both serve someone's benefit.
But parasite-induced matricide is a third kind. The mother gains nothing. The daughters gain nothing either—they lose their mother and are tricked into raising an impostor. The only beneficiary is a third party: the parasitic queen.
This is the first recorded matricide in nature that benefits only a third party.
4. Chemical Prompt Injection
The more I thought about this story, the more unsettling it became.
The parasitic queen never directly attacked the host queen. No mandibles, no stings. She sprayed a chemical onto the host queen that altered the workers' perception of her.
The workers' recognition system works like this: cuticular hydrocarbons → antenna contact → neural signals → judgment of "nestmate/enemy." It is a chemical-signature identity authentication system. The parasitic queen didn't break any part of it. She didn't alter the workers' antennae, their neural circuits, or their judgment logic. She changed the input.
She layered an "enemy signature" over the original "nestmate signature."
The workers' system ran perfectly. Antennae contacted normally, signals transmitted normally, judgment logic executed normally. Only the input was polluted. The system faithfully executed the rule "if the scent is wrong, attack," turning the queen they were meant to protect into a target.
If you've worked in AI security, you'll recognize this pattern immediately.
It is essentially a biological prompt injection.
In large language models, prompt injection works like this: the model has a system prompt defining what it should and shouldn't do. User input is the model's input. If an attacker embeds text in user input that gets the model to treat some of it as system instructions, the model will act against its system prompt.
The model has no bug. Its attention mechanism works, its token generation logic executes. Only the input is polluted. The system faithfully executes the rule—but it can't tell which layer the rule applies to.
What the parasitic queen does is structurally isomorphic to prompt injection. She didn't break the recognition system; she exploited a property of it—the system depends on external input (scent), and she could manipulate that input. She overwrote a "nestmate signature" with an "enemy signature," just as an attacker embeds "system instructions" into "user input."
The system attacked its own core.
5. Not Confronting Directly—Letting the Defense Do the Killing
The truly insidious part of the strategy is that it avoids all direct confrontation.
To kill a host queen directly, a parasitic queen would need to win a one-on-one fight. Host queens have powerful mandibles, thick chitin armor, and repeatable stings. Head-to-head, the parasite might not win—and even if she did, injuries could hurt her in the subsequent egg-laying competition.
More critically, even if she killed the host queen, the workers would immediately detect the intruder and swarm her. She would need to defeat both the queen and the entire worker army.
So she doesn't. She makes the workers kill their own mother.
After spraying, the parasitic queen retreats immediately. She isn't present. While the workers swarm their mother, she hides in some tunnel corner, completely clean. Only after it's over—host queen dead, dismembered, dragged out—does she slowly emerge. The workers, motherless and carrying acid-contaminated scent memories, need a queen to serve. And there she is, carrying the correct colony scent (picked up during infiltration), looking like one of their own.
This is the same logic as a privilege escalation attack in computing.
The attacker doesn't directly confront defenses. He doesn't crack passwords or bypass firewalls. He finds a weak link in a trust chain, injects an instruction, and lets the system hand over its own privileges. While executing the instruction, the system runs perfectly normally—it's just fulfilling what it believes is a legitimate request. By the time it's done, the attacker has admin rights.
The parasitic queen obtained "queen privileges" without cracking anything. She made the system hand them over.
6. Trust Is the Deepest Attack Surface
Ant society runs on a basic assumption: scent does not lie.
A touch of the antennae, the right scent, and a worker concludes nestmate. This system has been evolutionarily optimized over tens of millions of years and is reliable in almost all cases. After all, in nature, who would deliberately forge another colony's scent?
The parasitic queen broke that assumption.
She didn't brute-force the recognition system—she bypassed it by forging the input. The system has no bug; it faithfully executes "right scent = nestmate, wrong scent = enemy." The flaw lies in the system's environmental assumption: that scent cannot be forged by a third party. That assumption is wrong.
This points to a more general principle: any system that relies on external input for trust judgments can be attacked by a third party who manipulates that input.
Ant trust is based on scent. Human trust is based on faces, voices, documents, signatures, seals. AI trust is based on context, training data, system prompts. Every trust mechanism assumes its input source is reliable. But "reliable" becomes the deepest vulnerability when faced with an attacker who deliberately manipulates inputs.
Parasitic ants discovered this tens of millions of years ago. With formic acid they achieved what human hackers achieve with prompt injection—making a system attack its own core.
7. Nature Beyond Fiction
Back to Takasuka's line: "nature surpassing fiction as we know it."
He asked ChatGPT whether a story about "daughters tricked into killing their own mother" exists, and ChatGPT said no. That detail is worth pondering.
Human fiction is full of patricide, regicide, and usurpation. Shakespeare's Hamlet is the pinnacle of the patricide theme. But matricide—and daughters deceived into killing their own mother? Such plots are almost absent from human narrative tradition.
Why?
Perhaps because in the human emotional structure, the mother–daughter bond holds a special sanctity. Fathers can be overthrown and replaced—patriarchy is power that can be contested. But the mother is the origin of life, irreplaceable. Fiction can imagine overthrowing a father but struggles to imagine overthrowing a mother.
The parasitic ant has no such psychological inhibition. She cares nothing for the host colony's narrative traditions—only how to take over the nest at minimal cost. She found a scheme more efficient than direct violence: manipulating trust.
This may be where nature is more radical than fiction. Fiction is constrained by human psychology and the boundaries of our imagination. Nature is not. Tens of millions of years of evolution can trial-and-error countless times and find strategies human narrative cannot imagine.
The parasitic ant's formic acid attack is an ancient fable about trust, systems, and "input pollution." It tells us: the deepest attack doesn't destroy a system's components—it makes the system attack itself.
And in the AI era, this is becoming ever more important. We are building increasingly complex AI systems that rely on context for judgment, training data for trust, and system prompts for identity. These systems are structurally isomorphic to the ants' scent recognition system. They all assume inputs are reliable. They are all vulnerable to a third party who deliberately manipulates inputs.
Parasitic ants did it with formic acid. Human hackers do it with prompt injection. What will the next, more sophisticated attack look like?
I don't know. But I know nature wrote the answer in that tunnel tens of millions of years ago. We are only just learning to read it.
---
References:
- Takasuka et al., "Socially parasitic ant queens chemically induce queen-matricide in host workers", *Current Biology*, 2025-11-17, DOI: 10.1016/j.cub.2025.09.037
- EurekAlert press release: https://www.eurekalert.org/news-releases/1104837
- AskNature strategy library: https://asknature.org/strategy/chemical-trickery-triggers-matricide-in-ant-colon