The post Security analysts warn of ‘expanded attack surface’ as AI agents become default appeared on BitcoinEthereumNews.com. The use of AI agents has become increasinglyThe post Security analysts warn of ‘expanded attack surface’ as AI agents become default appeared on BitcoinEthereumNews.com. The use of AI agents has become increasingly

Security analysts warn of ‘expanded attack surface’ as AI agents become default

2026/03/18 23:18
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

The use of AI agents has become increasingly popular among traders. However, SlowMist has shared findings on possible attack vectors, cautioning users to pump the brakes to protect themselves against bad actors. 

Traders are being warned to limit the permissions granted to their AI agents, as they can be very easily compromised. With limited access, even if they get hacked, the damage will be minimized.

Can hackers steal your money by tricking AI agents?

Usually, a hacker would have to trick a user into clicking a link in order to extort them. But now, they only need to trick whatever AI agent is being used.

Cryptopolitan recently reported that a Solana AI agent gave away $441K worth of Lobstar tokens after being tricked on social media. However, it is unclear whether or not the incident was staged to draw attention to the memecoin.

Polymarket recently confirmed a security breach involving a third-party authentication provider, Magic Labs, which resulted in multiple user accounts being drained despite having two-factor authentication enabled. It is estimated that the total losses exceed $500,000.

The incident occurred in December of 2025, and 23pds, the CISO of SlowMist, flagged a malicious copy-trading bot on GitHub containing code designed to compromise Polymarket accounts.

Most recently, SlowMist released a report stating that the most dangerous new weapon is Indirect Prompt Injection.

This is particularly effective in the Skills ecosystem, like Bitget’s Agent Hub or the open-source OpenClaw.

SlowMist researchers monitored ClawHub and found that nearly 10% of available plugins contained two-stage malware. The first stage looks legitimate, but once installed, it downloads the malware that then scrapes local machine info, browser cookies, and SSH keys.

In the event that AI agents are running 24/7, these thefts can go undetected for weeks.

Recent 2026 reports from Oasis Security identified a high-severity vulnerability called ClawJacked (CVSS 8.0+). This flaw allows malicious websites to hijack a user’s locally running AI agent through a simple browser visit.

How to avoid AI agent losses

The Bitget security team report suggests a 5-layer security system that focuses on “least privilege.” If your AI agent is only supposed to analyze charts, it should not have the permission to execute trades. If it trades, it should never have the permission to withdraw.

First, Passkeys (FIDO2/WebAuthn) should be the primary login method. Passkeys use public-private key encryption that makes phishing attacks impossible.

Even if an attacker is able to lead a user to a fake login page, the hardware-backed security will not release the credentials, keeping their account safe from unauthorized access.

Secondly, rather than using a main account API key, traders should create dedicated sub-accounts for their AI agents and transfer only the necessary funds to these sub-accounts. Even if a leak occurs, users can effectively limit the impact.

IP Whitelisting is already a compulsory step for any automated setup that ensures that the exchange only accepts commands coming from a specific, approved server address.

AI agent users should implement .agentignorefiles to prevent it from reading or registering sensitive local files during its everyday tasks.

The report also stresses the importance of having human supervision when it comes to high-value operations.

Even without hacks, letting an AI run totally “hands-off” is a financial risk.

The Nov1.ai experiment in late 2025 showed that GPT-5 suffered from “analysis paralysis” and lost over 60% of its capital in two weeks, while Gemini became an “over-trader” and racked up massive fees that wiped out its gains.

Source: https://www.cryptopolitan.com/analysts-warn-of-attack-ai-agents/

Piyasa Fırsatı
Lobstar Logosu
Lobstar Fiyatı(LOBSTAR)
$0.003459
$0.003459$0.003459
-4.63%
USD
Lobstar (LOBSTAR) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Today’s Biggest Crypto Movers: Dogecoin Leads the Pack

Today’s Biggest Crypto Movers: Dogecoin Leads the Pack

Today's Biggest Crypto Movers: Dogecoin Leads the Pack 🚀 Crypto Markets Heat Up Today Major cryptocurrencies are showing strong gains. Let's dive into today's top
Paylaş
Blockchainmagazine2026/04/03 13:00
RWA Boom Accelerates As Tokenized Assets Hit New Highs In Early 2026

RWA Boom Accelerates As Tokenized Assets Hit New Highs In Early 2026

RWA distributed value rose from about $21B to $27.5B in Q1 2026, a gain of roughly 30%. Tokenized US Treasuries reached about $10B, creating an on-chain yield base
Paylaş
LiveBitcoinNews2026/04/03 13:00
Cryptos Signal Divergence Ahead of Fed Rate Decision

Cryptos Signal Divergence Ahead of Fed Rate Decision

The post Cryptos Signal Divergence Ahead of Fed Rate Decision appeared on BitcoinEthereumNews.com. Crypto assets send conflicting signals ahead of the Federal Reserve’s September rate decision. On-chain data reveals a clear decrease in Bitcoin and Ethereum flowing into centralized exchanges, but a sharp increase in altcoin inflows. The findings come from a Tuesday report by CryptoQuant, an on-chain data platform. The firm’s data shows a stark divergence in coin volume, which has been observed in movements onto centralized exchanges over the past few weeks. Bitcoin and Ethereum Inflows Drop to Multi-Month Lows Sponsored Sponsored Bitcoin has seen a dramatic drop in exchange inflows, with the 7-day moving average plummeting to 25,000 BTC, its lowest level in over a year. The average deposit per transaction has fallen to 0.57 BTC as of September. This suggests that smaller retail investors, rather than large-scale whales, are responsible for the recent cash-outs. Ethereum is showing a similar trend, with its daily exchange inflows decreasing to a two-month low. CryptoQuant reported that the 7-day moving average for ETH deposits on exchanges is around 783,000 ETH, the lowest in two months. Other Altcoins See Renewed Selling Pressure In contrast, other altcoin deposit activity on exchanges has surged. The number of altcoin deposit transactions on centralized exchanges was quite steady in May and June of this year, maintaining a 7-day moving average of about 20,000 to 30,000. Recently, however, that figure has jumped to 55,000 transactions. Altcoins: Exchange Inflow Transaction Count. Source: CryptoQuant CryptoQuant projects that altcoins, given their increased inflow activity, could face relatively higher selling pressure compared to BTC and ETH. Meanwhile, the balance of stablecoins on exchanges—a key indicator of potential buying pressure—has increased significantly. The report notes that the exchange USDT balance, around $273 million in April, grew to $379 million by August 31, marking a new yearly high. CryptoQuant interprets this surge as a reflection of…
Paylaş
BitcoinEthereumNews2025/09/18 01:01

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity