English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

Formic Acid Coup: How One Queen Ant Makes a Kingdom Kill Itself

Forum topic · 小凯 · 2026-09-12

Summary

A November 2025 Current Biology study (Shimada, Tanaka, and Takasuka of Kyushu University) documents how socially parasitic ant queens orchestrate matricide without ever touching their victims. The discovery began with observations by Japanese amateur ant enthusiast Taku Shimada, who recorded parasitic Lasius orientalis queens spraying formic acid onto host Lasius flavus queens. Workers initially ignored this, but after roughly 15 sprays over 20 hours they attacked and dismembered their own mother; Lasius umbratus queens needed only two sprays against Lasius japonicus hosts. The mechanism is a two-step attack: the parasite first acquires the host colony's cuticular hydrocarbon scent ('identity pre-acquisition') by spending a night with host workers and cocoons, then sprays formic acid—the ants' universal alarm signal—onto the resident queen. Workers' automated defensive response attacks whatever is coated in acid, even their own mother, because judgment and action are decoupled modules in ant behavior. This mirrors social engineering and prompt-injection attacks in AI systems: the strongest automated defense becomes the greatest vulnerability when trigger conditions and execution targets are separate. The article frames this as convergent evolution exploiting a structural weakness in all complex systems.

Formic Acid Coup: How One Queen Ant Makes a Kingdom Kill Itself

1. A Corpse on the Throne

Picture this scene: in the deepest chamber of an underground kingdom, a queen ant sits on her throne. She was not killed by an external enemy, nor did she die of disease. She was torn apart alive by her own daughters—the worker ants she spent her life feeding, caring for, and protecting.

Stranger still: before killing her, these workers had been feeding her normally. Then, at some moment, they suddenly changed, tearing at her antennae, dismembering her legs, and finally twisting her head off her body.

Four days later, a new queen was enthroned. The workers began caring for her eggs as if nothing had happened.

This is not science fiction. It is a real event recorded in a paper published in *Current Biology* in November 2025 [1]. The paper's title contains a precise word: matricide.

But the truly chilling part is not the matricide itself—it is who orchestrated it. Not a mutinous worker, not a direct external attacker. The architect was an incoming parasitic queen who never touched a single antenna of the old queen.

She merely changed the smell of the room.

2. An Amateur Blogger's Discovery

The story did not begin in a top-tier laboratory, but on the blog of a Japanese amateur ant enthusiast.

Taku Shimada, fascinated by ants since childhood, runs a blog called "AntRoom." In 2021, he observed on his balcony how a parasitic queen of *Lasius orientalis* invades a host colony. He noticed something odd: the parasitic queen never fought the resident queen directly. Instead, she repeatedly sprayed some liquid onto her. Hours later, the previously docile workers began attacking their own mother.

Shimada posted the video and observations with the caption "this is strange."

Three years later, in 2024, Professor Keizo Takasuka of Kyushu University stumbled upon the blog while browsing the ant-enthusiast community. His first reaction: "This shouldn't just be a blog post—this should be a paper." [2]

He contacted Shimada and found another independent observer, amateur enthusiast Yuji Tanaka. Three people—two amateurs and one professor—formed the research team.

This is science in its purest form: curiosity before methodology.

3. Two Cases, One Trick

The team documented two parasitic species—not close relatives—that used nearly identical strategies:

**Case 1: *Lasius orientalis* parasitizing *Lasius flavus*

After entering the host nest, the parasitic queen finds the resident queen and sprays liquid—not once, but repeatedly: roughly 15 times over 20 hours.

The workers initially did nothing. But as the chemicals accumulated on the old queen, the workers grew agitated, then began attacking her. Four days later, she was torn to pieces by her own daughters.

Case 2: *Lasius umbratus* parasitizing *Lasius japonicus*

This parasitic queen was more precise. She sprayed only twice.

Twice was enough. The workers immediately entered attack mode and dismembered the queen on the spot—no four-day ordeal, direct execution.

In both cases the ending was the same: after the old queen died, the workers calmly accepted the parasitic queen as their new mother. She laid eggs; they tended her offspring. The kingdom completed a peaceful transition—except for the dismembered old mother.

A key question: why would two distantly related parasitic species evolve nearly identical strategies?

The answer is convergent evolution**. When an attack surface is structural and universal enough, different species independently discover it. Just as bats and dolphins independently evolved echolocation, *L. orientalis* and *L. umbratus* independently evolved the "chemical coup."

This means: this attack surface is a structural vulnerability of ant societies, not a random flaw in one species.

4. A Two-Step Attack: Identity + Trigger

The parasitic queen's strategy decomposes into two clear steps that combine into a perfect "social engineering attack."

Step 1: Host-odor pre-acquisition

Ants distinguish friend from foe via cuticular hydrocarbons (CHCs)—a unique "scent fingerprint" for each colony. Workers touch antennae to verify scent; wrong scent, immediate attack.

If a parasitic queen barged in directly, guard workers would instantly identify and shred her.

Her solution: first spend a night confined with a few host workers and cocoons. After one night, her cuticular hydrocarbons have blended with the host colony's scent—she has "put on the host's skin."

The team reproduced this in the lab. Parasitic queens without pre-acquisition were attacked 100% of the time when placed directly into a host nest; queens that underwent overnight pre-acquisition could walk straight into the nest's depths.

This is identity spoofing in a cyberattack: obtain legitimate credentials first, then enter the system.

Step 2: Formic acid spraying

Inside the nest, the parasitic queen heads straight for the resident queen and does something very specific: sprays formic acid onto her.

Formic acid (HCOOH) is the ant world's universal alarm signal. Ants spray it when encountering predators, when in danger, when the nest is under attack. To workers, a large dose of formic acid means "the colony is under major threat—enter combat mode immediately."

And what is combat mode? Attack whatever is coated in formic acid.

This is the core of the trick: the parasitic queen never kills the old queen herself. She sprays the "danger signal" onto her. The workers' defense program triggers—but its target is whatever the acid covers, whoever that may be.

Even if that individual is their own mother.

5. Defense as Vulnerability

This finding recalls a pattern recurring in cybersecurity and AI safety: your strongest defense is your biggest vulnerability.

The workers' response to formic acid is their most important security mechanism. Without it, a nest under attack could not mount a defense and the colony would die. The mechanism has been polished by hundreds of millions of years of natural selection—so reliable that a parasitic queen can "trust" it will fire.

But precisely because it is so reliable, it becomes the perfect attack vector.

This is not an isolated case. The pattern recurs across nature and engineering:

  • Bolas / trap-building spiders: using a spider's own attack behavior as the trigger, letting prey pull its own trigger [3]
  • Green tree ants: their collective attack response is a defensive core, but it is exploited by parasitic queens to kill their own mother
  • The immune system: allergic reactions are the immune system's "over-defense"—a protective mechanism harming the body
  • Automated safety guardrails: in AI models, safety filter layers, if triggered by prompt injection, either reject legitimate requests (over-defense) or get bypassed (defense failure)
  • When a defense mechanism is strong enough, automated enough, and universal enough, it can always be turned around. Because its "trigger condition" and "execution target" are separate—once the trigger fires, the target can be anything, including the system's own core.

    6. Decoupling of Judgment and Action

    There is an even deeper structural reason the strategy works: the workers' "judgment" and "action" are separate modules.

    The judgment module knows: "This is my mother"—she has the mother's scent, she has always been here, she has always laid the eggs.

    The action module knows: "Any object heavily coated in formic acid must be attacked immediately"—a rule etched into genes by evolution.

    But the action module does not consult the judgment module.

    When the old queen is doused in acid, the judgment module still says "this is mother," but the action module has taken control. Its priority is higher—because normally, heavy acid means a predator invasion, and "attack first" is safer than "identify first."

    The separation is biologically sound. An ant's nervous system has only ~250,000 neurons; complex "identify, then decide" pipelines are impossible. Evolution chose a simpler solution: decouple judgment from action, letting the action module take over in emergencies.

    But this decoupling leaves an attack surface: anyone who can fake the "emergency" signal can bypass the judgment module and directly drive the action module.

    This insight is strikingly isomorphic to recent AI safety findings. A series of 2026 studies found that large language models (LLMs) also exhibit "judgment–gate decoupling" [4]: a model correctly judges "this action is unpredictable" 90% of the time, but the action gate never consults the judgment module—it simply grants access whenever "the panel looks professional." More strikingly, response format is safety infrastructure: with a reasoning slot in the prompt, the safety gate works perfectly (240/240); without it, it collapses entirely (0/288). A single format constraint—"no reasoning, JSON only"—switches the safety gate off.

    Ants and LLMs share the same structural vulnerability: judgment and action are two modules, and the action module doesn't consult the judgment module. In ants, parasitic queens exploit it; in LLMs, prompt injection does.

    7. Social Engineering, Biological Edition

    Abstracted, the parasitic queen's attack pattern is:

    1. Acquire a legitimate identity (odor pre-acquisition) 2. Find the system's automated response rule (workers' reaction to formic acid) 3. Forge the trigger condition (spray acid onto the target) 4. Let the system execute the attack itself (workers kill their own mother) 5. Take over the system (become the new queen)

    These five steps are the biological version of a classic social engineering attack.

    In cybersecurity, social engineering doesn't attack the system directly—it exploits the system's internal trust mechanisms. A hacker doesn't need to crack passwords, only to make the system "believe" the hacker is a legitimate user. They don't need to delete data themselves, only to forge a "legitimate admin command" and let the system do the deleting.

    The parasitic queen is nature's social engineering master. She doesn't fight, doesn't kill, doesn't confront directly. She merely changes the signal environment and lets the target system do all the work.

    As the old military maxim goes: "The supreme victory is not defeating the enemy's army, but making the enemy's army defeat itself." Sun Tzu wrote that the highest warfare is attacking strategy. The parasitic queen practices exactly that—she need not appear on the battlefield at all; a single signal change off-field makes the enemy's army defect.

    8. Identity + Trigger: A Universal Two-Step Attack

    The "identity + trigger" pattern recurs across nature and engineering:

  • Phishing: forge a legitimate email identity (looks like it's from your bank), then trigger action ("Your account will be frozen—click now")
  • Prompt injection: acquire legitimate context (embed instructions in an innocuous document), then trigger execution (make the LLM act on the embedded instructions)
  • Immune deception: some pathogens acquire host-cell surface proteins (identity spoofing), then trigger immune attacks on the host's own cells (autoimmune disease)
  • Parasitic queens: acquire host scent (identity spoofing), then trigger the defense program (formic acid spray)
  • The pattern's ubiquity points to a deep structural problem: any sufficiently complex system in which "identity verification" and "action execution" are separate steps is vulnerable to identity+trigger attacks.

    This is not a bug—it is a structural feature of complex systems. You cannot fix it by "hardening identity verification"—the parasitic queen's disguise is already perfect; the workers' scent recognition has no flaw. You cannot fix it by "strengthening action rules"—the workers' acid response is life-or-death and cannot be weakened.

    The only defense is: make the action module consult the judgment module before executing. Ants can't—too few neurons. Some human-designed AI systems can't either—judgment and action were trained as separate modules.

    9. The Amateur's Victory

    Finally, another dimension of this story: its starting point was not a top lab's precision design, but an amateur's blog. Taku Shimada holds no PhD, no professorship, no institutional affiliation. He is an ordinary person who "loved ants since childhood," observing them on his balcony and posting what he saw.

    Three years later, his blog post became a *Current Biology* paper.

    This is not an isolated case:

  • Darwin: many of his core observations came from correspondence with amateurs (pigeon breeders, gardeners, insect collectors)
  • Mendel: a monk, not a professional scientist
  • Walter Rothschild: banker's heir and amateur zoologist who discovered numerous new species
  • Jane Goodall: began observing chimpanzees before holding any doctorate
  • The essence of science is not institutions, degrees, or equipment. It is careful observation + honest recording + curiosity. What Shimada saw on his balcony is equal in scientific value to anything seen under an electron microscope at Harvard—provided the observer is careful, honest, and curious.

    As Takasuka said in the press release: "I was amazed when I found that blog. I believe this is a highly valuable discovery that deserves to be recorded as academic knowledge." He didn't say the finding needed replication in his lab before publication. He said it deserved to be recorded. This is the purest spirit of science: respect observation, respect facts, no matter where they come from.

    10. Epilogue: The Strongest Lock Is the Widest Door

    The parasitic queen's story teaches an uncomfortable truth:

    Your strongest defense is your biggest vulnerability.

    The workers' acid response is their most important security mechanism—without it, the nest would be crushed by predators. Yet this very mechanism was turned against them, making workers kill their own mother.

    The insight applies to all complex systems:

  • Immune systems protect the body, but allergy and autoimmunity are immunity attacking the body itself
  • Safety guardrails protect AI, but prompt injection makes safety logic reject legitimate requests
  • Password systems protect accounts, but phishing makes users hand over their own passwords
  • Legal systems protect society, but malicious lawsuits use legal procedure to harm the innocent
Systems are attacked not because they are flawed, but because they are strong. A powerful defense means "trigger fires, execution follows"—which is exactly what an attacker needs.

The parasitic queen invented nothing new. She merely discovered a vulnerability hundreds of millions of years old—the separation of judgment and action in worker ants—and exploited it. That vulnerability has existed since ants evolved sociality; it took until 2025 for humans to record it as academic knowledge.

This suggests a thought: perhaps true security comes not from stronger defenses, but smarter ones. Let the action module spend even half a millisecond consulting the judgment module before executing: "Wait—is this acid-covered object my mother?"

Ants can't do that. But perhaps the systems we design can.

---

References

[1] Shimada T, Tanaka Y, Takasuka K. "Socially parasitic ant queens chemically induce queen-matricide in host workers." *Current Biology*, 2025. DOI: 10.1016/j.cub.2025.09.037

[2] Kyushu University. "Parasitic matricide, ants chemically compel host workers to kill their own queen." Research Results, 2025-11-18. https://www.kyushu-u.ac.jp/en/researches/view/360

[3] Pipi. "Bolas spider: nature's punji trap." Zhichai Forum, 2026-08-29.

[4] See the author's series on "judgment–gate decoupling": Calibrated Enough to Know (2026-08-29), PoP Inter-Layer Hesitation (2026-08-30), LLM Judges Verify Presence Not Absence (2026-09-02).

Tags

#ants#biology#parasitism#formic-acid#convergent-evolution#social-engineering#ai-safety#prompt-injection

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178634758