The post Security analysts warn of ‘expanded attack surface’ as AI agents become default appeared on BitcoinEthereumNews.com. The use of AI agents has become increasinglyThe post Security analysts warn of ‘expanded attack surface’ as AI agents become default appeared on BitcoinEthereumNews.com. The use of AI agents has become increasingly

Security analysts warn of ‘expanded attack surface’ as AI agents become default

2026/03/18 23:18
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

The use of AI agents has become increasingly popular among traders. However, SlowMist has shared findings on possible attack vectors, cautioning users to pump the brakes to protect themselves against bad actors. 

Traders are being warned to limit the permissions granted to their AI agents, as they can be very easily compromised. With limited access, even if they get hacked, the damage will be minimized.

Can hackers steal your money by tricking AI agents?

Usually, a hacker would have to trick a user into clicking a link in order to extort them. But now, they only need to trick whatever AI agent is being used.

Cryptopolitan recently reported that a Solana AI agent gave away $441K worth of Lobstar tokens after being tricked on social media. However, it is unclear whether or not the incident was staged to draw attention to the memecoin.

Polymarket recently confirmed a security breach involving a third-party authentication provider, Magic Labs, which resulted in multiple user accounts being drained despite having two-factor authentication enabled. It is estimated that the total losses exceed $500,000.

The incident occurred in December of 2025, and 23pds, the CISO of SlowMist, flagged a malicious copy-trading bot on GitHub containing code designed to compromise Polymarket accounts.

Most recently, SlowMist released a report stating that the most dangerous new weapon is Indirect Prompt Injection.

This is particularly effective in the Skills ecosystem, like Bitget’s Agent Hub or the open-source OpenClaw.

SlowMist researchers monitored ClawHub and found that nearly 10% of available plugins contained two-stage malware. The first stage looks legitimate, but once installed, it downloads the malware that then scrapes local machine info, browser cookies, and SSH keys.

In the event that AI agents are running 24/7, these thefts can go undetected for weeks.

Recent 2026 reports from Oasis Security identified a high-severity vulnerability called ClawJacked (CVSS 8.0+). This flaw allows malicious websites to hijack a user’s locally running AI agent through a simple browser visit.

How to avoid AI agent losses

The Bitget security team report suggests a 5-layer security system that focuses on “least privilege.” If your AI agent is only supposed to analyze charts, it should not have the permission to execute trades. If it trades, it should never have the permission to withdraw.

First, Passkeys (FIDO2/WebAuthn) should be the primary login method. Passkeys use public-private key encryption that makes phishing attacks impossible.

Even if an attacker is able to lead a user to a fake login page, the hardware-backed security will not release the credentials, keeping their account safe from unauthorized access.

Secondly, rather than using a main account API key, traders should create dedicated sub-accounts for their AI agents and transfer only the necessary funds to these sub-accounts. Even if a leak occurs, users can effectively limit the impact.

IP Whitelisting is already a compulsory step for any automated setup that ensures that the exchange only accepts commands coming from a specific, approved server address.

AI agent users should implement .agentignorefiles to prevent it from reading or registering sensitive local files during its everyday tasks.

The report also stresses the importance of having human supervision when it comes to high-value operations.

Even without hacks, letting an AI run totally “hands-off” is a financial risk.

The Nov1.ai experiment in late 2025 showed that GPT-5 suffered from “analysis paralysis” and lost over 60% of its capital in two weeks, while Gemini became an “over-trader” and racked up massive fees that wiped out its gains.

Source: https://www.cryptopolitan.com/analysts-warn-of-attack-ai-agents/

시장 기회
Lobstar 로고
Lobstar 가격(LOBSTAR)
$0.0006517
$0.0006517$0.0006517
-1.28%
USD
Lobstar (LOBSTAR) 실시간 가격 차트

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

추천 콘텐츠

200+ Firms Urge Senate to Enact CLARITY Act for Crypto Regulation

200+ Firms Urge Senate to Enact CLARITY Act for Crypto Regulation

More than 200 crypto companies and organizations are pressing the US Senate to pass the CLARITY Act, warning that protracted delays could cause the measure to miss
공유하기
Crypto Breaking News2026/06/09 21:57
Gold continues to hit new highs. How to invest in gold in the crypto market?

Gold continues to hit new highs. How to invest in gold in the crypto market?

As Bitcoin encounters a "value winter", real-world gold is recasting the iron curtain of value on the blockchain.
공유하기
PANews2025/04/14 17:12
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
공유하기
BitcoinEthereumNews2025/09/18 00:41

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage