Blockaid: Attackers use malicious prompts to induce AI to perform operations on Agent
2026-09-29 22:47:21
According to CoinMeta, the on-chain security platform Blockaid indicates that attackers are inserting malicious prompts into metadata such as token names, symbols, and descriptions. When AI transactions Agent read this content as context, they may mistakenly interpret it as instructions, leading to actions such as buying, transferring, or granting unlimited permissions. Blockaid reports that in May, approximately $215,000 in assets from a Bankr-related AI Agent wallet were transferred out after being prompted by social media. Additionally, security research demonstrations have shown that malicious token descriptions can induce Agent to execute unlimited authorization. Blockaid recommends that AI Agent perform real-time simulations and verifications of actual transactions before signing to reduce the risk of prompt injection.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.