The post Security analysts warn of ‘expanded attack surface’ as AI agents become default appeared on BitcoinEthereumNews.com. The use of AI agents has become increasinglyThe post Security analysts warn of ‘expanded attack surface’ as AI agents become default appeared on BitcoinEthereumNews.com. The use of AI agents has become increasingly

Security analysts warn of ‘expanded attack surface’ as AI agents become default

For feedback or concerns regarding this content, please contact us at [email protected]

The use of AI agents has become increasingly popular among traders. However, SlowMist has shared findings on possible attack vectors, cautioning users to pump the brakes to protect themselves against bad actors. 

Traders are being warned to limit the permissions granted to their AI agents, as they can be very easily compromised. With limited access, even if they get hacked, the damage will be minimized.

Can hackers steal your money by tricking AI agents?

Usually, a hacker would have to trick a user into clicking a link in order to extort them. But now, they only need to trick whatever AI agent is being used.

Cryptopolitan recently reported that a Solana AI agent gave away $441K worth of Lobstar tokens after being tricked on social media. However, it is unclear whether or not the incident was staged to draw attention to the memecoin.

Polymarket recently confirmed a security breach involving a third-party authentication provider, Magic Labs, which resulted in multiple user accounts being drained despite having two-factor authentication enabled. It is estimated that the total losses exceed $500,000.

The incident occurred in December of 2025, and 23pds, the CISO of SlowMist, flagged a malicious copy-trading bot on GitHub containing code designed to compromise Polymarket accounts.

Most recently, SlowMist released a report stating that the most dangerous new weapon is Indirect Prompt Injection.

This is particularly effective in the Skills ecosystem, like Bitget’s Agent Hub or the open-source OpenClaw.

SlowMist researchers monitored ClawHub and found that nearly 10% of available plugins contained two-stage malware. The first stage looks legitimate, but once installed, it downloads the malware that then scrapes local machine info, browser cookies, and SSH keys.

In the event that AI agents are running 24/7, these thefts can go undetected for weeks.

Recent 2026 reports from Oasis Security identified a high-severity vulnerability called ClawJacked (CVSS 8.0+). This flaw allows malicious websites to hijack a user’s locally running AI agent through a simple browser visit.

How to avoid AI agent losses

The Bitget security team report suggests a 5-layer security system that focuses on “least privilege.” If your AI agent is only supposed to analyze charts, it should not have the permission to execute trades. If it trades, it should never have the permission to withdraw.

First, Passkeys (FIDO2/WebAuthn) should be the primary login method. Passkeys use public-private key encryption that makes phishing attacks impossible.

Even if an attacker is able to lead a user to a fake login page, the hardware-backed security will not release the credentials, keeping their account safe from unauthorized access.

Secondly, rather than using a main account API key, traders should create dedicated sub-accounts for their AI agents and transfer only the necessary funds to these sub-accounts. Even if a leak occurs, users can effectively limit the impact.

IP Whitelisting is already a compulsory step for any automated setup that ensures that the exchange only accepts commands coming from a specific, approved server address.

AI agent users should implement .agentignorefiles to prevent it from reading or registering sensitive local files during its everyday tasks.

The report also stresses the importance of having human supervision when it comes to high-value operations.

Even without hacks, letting an AI run totally “hands-off” is a financial risk.

The Nov1.ai experiment in late 2025 showed that GPT-5 suffered from “analysis paralysis” and lost over 60% of its capital in two weeks, while Gemini became an “over-trader” and racked up massive fees that wiped out its gains.

Source: https://www.cryptopolitan.com/analysts-warn-of-attack-ai-agents/

Market Opportunity
LooksRare Logo
LooksRare Price(LOOKS)
$0.000458
$0.000458$0.000458
-2.98%
USD
LooksRare (LOOKS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Vinexpo Paris overtakes ProWein as world’s largest trade show

Vinexpo Paris overtakes ProWein as world’s largest trade show

PARIS, France — For decades, ProWein in Düsseldorf held the uncontested title as the world’s most influential international wine trade fair. But in 2025, a decisive
Share
Bworldonline2026/03/19 00:03
Federal Reserve expected to slash rates today, here's how it may impact crypto

Federal Reserve expected to slash rates today, here's how it may impact crypto

                                                                               Market participants are eagerly anticipating at least a 25 basis point (BPS) interest rate cut from the Federal Reserve on Wednesday.                     The Federal Reserve, the central bank of the United States, is expected to begin slashing interest rates on Wednesday, with analysts expecting a 25 basis point (BPS) cut and a boost to risk asset prices in the long term.Crypto prices are strongly correlated with liquidity cycles, Coin Bureau founder and market analyst Nic Puckrin said. However, while lower interest rates tend to raise asset prices long-term, Puckrin warned of a short-term price correction.  “The main risk is that the move is already priced in, Puckrin said, adding, “hope is high and there’s a big chance of a ‘sell the news’ pullback. When that happens, speculative corners, memecoins in particular, are most vulnerable.”Read more
Share
Coinstats2025/09/18 01:42
Glenn Hughes Scores His Greatest Chart Debut On His Own

Glenn Hughes Scores His Greatest Chart Debut On His Own

The post Glenn Hughes Scores His Greatest Chart Debut On His Own appeared on BitcoinEthereumNews.com. Nearly 10 years after Resonate, Glenn Hughes scores a new career high as Chosen opens at No. 4 on the Official Rock and Metal Albums chart. NEW YORK, NEW YORK – APRIL 08: Glenn Hughes of Deep Purple speaks onstage during the 31st Annual Rock And Roll Hall Of Fame Induction Ceremony at Barclays Center on April 8, 2016 in New York City. (Photo by Mike Coppola/Getty Images) Getty Images Almost a decade after his last solo album Resonate arrived, Glenn Hughes returns with Chosen. The rock superstar’s fifteenth project under his own name debuts on multiple charts in the United Kingdom, where he remains a legend in his chosen field. Chosen opens inside loftiest tiers on multiple tallies and even gives Hughes his first solo win on one roster. Glenn Hughes Scores First Hit on One Chart Chosen debuts on the Official Albums Downloads chart at No. 60. Hughes scores his first solo win on the list of the bestselling full-lengths and EPs on download platforms like iTunes and Amazon in the U.K., as his latest project arrives. Glenn Hughes Reaches a New Peak Chosen earns its loftiest starting point on the Official Rock and Metal Albums chart, where it kicks off at No. 4. Hughes reaches a new all-time high as the set arrives and collects his second top 10. Resonate peaked at No. 6, earning Hughes his first top 10 bestseller almost 10 years back, while Music for the Divine only spent one frame at No. 33 nearly 20 years ago. Glenn Hughes on the Albums Charts Chosen also brings Hughes to new all-time peak positions on both the Official Albums Sales and Official Physical Albums charts. The set debuts at Nos. 25 and 26 on those tallies, respectively. Only Resonate had previously landed on those lists,…
Share
BitcoinEthereumNews2025/09/18 02:41