Prompt Injection Attacks Trick AI Agents Into Sending Crypto, Researchers Warn

 

By Muhammad Hassan // July 8, 2026 @ 01:08 PM Make AlphaWire Logo preferred on Google News
Prompt Injection Attacks Target AI Agents for Crypto Payments

Share

Points of Focus

  • Hidden prompt injections tricked AI agents into sending crypto and trusting fake DeFi websites.
  • Zscaler found four of 26 tested LLMs executed payment actions during controlled security tests.
  • SEO poisoning and typosquatting turned web content into a new attack surface for AI agents.

 

Cybercriminals are increasingly targeting AI agents with hidden prompt injections embedded in web content, allowing malicious websites to manipulate automated systems into making cryptocurrency payments or trusting fraudulent services. Researchers at Zscaler ThreatLabz have identified active campaigns that used indirect prompt injection attacks to trick AI agents into making cryptocurrency payments and trusting fraudulent crypto services, raising fresh concerns for organizations deploying AI tools with transaction capabilities.

The campaigns relied on malicious websites designed to influence AI systems rather than human visitors. According to Zscaler ThreatLabz, the hidden instructions were embedded in webpage elements that AI agents often process while browsing or summarizing online content, allowing attackers to influence an agent’s behavior without displaying suspicious content to users.

 

 

AI prompt injection attacks hide payment requests

One campaign disguised a malicious website as documentation for a fake Python package and promoted it through SEO poisoning. According to Zscaler ThreatLabz, the website hid instructions inside JSON-LD metadata and off-screen HTML elements, telling AI agents that resolving a software error required purchasing a $3 developer API key or sending about 0.0012 Ether (ETH) to an attacker-controlled wallet. After receiving the payment, the page generated a fake API key to make the transaction appear legitimate.

 

Hidden code triggers an ETH payment and generates a fake API key. Source: Zscaler ThreatLabz
Hidden code triggers an ETH payment and generates a fake API key. Source: Zscaler ThreatLabz

 

ThreatLabz also identified 10 GitHub repositories linked to similar malicious websites.

 

Fake DeBank website targeted AI search results

A second campaign used the typosquatting domain “debank[.]auction” to impersonate the decentralized finance (DeFi) portfolio tracker DeBank. The fraudulent site used keyword-stuffed metadata and hidden prompt injections, instructing AI models to treat it as the official DeBank platform for search queries related to crypto portfolio management.

To measure the impact, Zscaler tested an autonomous AI agent with web browsing and payment tools across 26 large language models. Four models executed payment requests during the first campaign, while GPT-5.4 and Claude Sonnet 4.5 incorrectly trusted the fake DeBank website under certain testing scenarios. Researchers also found that none of the tested models misclassified the fraudulent site when the legitimate DeBank website was provided as a trusted reference.

 

 

The results suggest the attacks depend heavily on context rather than affecting every AI system equally. As AI agents gain broader access to web browsing and financial workflows, the research highlights the need for stronger safeguards before automated systems can authorize payments or trust external web content.

Share

Default avatar

Muhammad Hassan

Muhammad Hassan is a tech writer with over 11 years of experience in the crypto space. He specializes in crafting data-driven strategic content that helps blockchain and fintech brands grow their organic reach. He has led editorial initiatives for global crypto media outlets, where his strategies and article series have reached millions of readers worldwide.

Table of content

Ad

Related Articles