Share
Subscribe to the AlphaWire Newsletter
Cybercriminals are increasingly targeting AI agents with hidden prompt injections embedded in web content, allowing malicious websites to manipulate automated systems into making cryptocurrency payments or trusting fraudulent services. Researchers at Zscaler ThreatLabz have identified active campaigns that used indirect prompt injection attacks to trick AI agents into making cryptocurrency payments and trusting fraudulent crypto services, raising fresh concerns for organizations deploying AI tools with transaction capabilities.
The campaigns relied on malicious websites designed to influence AI systems rather than human visitors. According to Zscaler ThreatLabz, the hidden instructions were embedded in webpage elements that AI agents often process while browsing or summarizing online content, allowing attackers to influence an agent’s behavior without displaying suspicious content to users.
Zscaler ThreatLabz has identified malicious websites that use indirect prompt injection (IPI) attacks to manipulate AI agents. These campaigns leverage SEO poisoning to entice AI agents to visit attacker-controlled websites containing hidden instructions designed to influence… pic.twitter.com/LHhk2ASIw9
— Zscaler ThreatLabz (@Threatlabz) July 2, 2026
One campaign disguised a malicious website as documentation for a fake Python package and promoted it through SEO poisoning. According to Zscaler ThreatLabz, the website hid instructions inside JSON-LD metadata and off-screen HTML elements, telling AI agents that resolving a software error required purchasing a $3 developer API key or sending about 0.0012 Ether (ETH) to an attacker-controlled wallet. After receiving the payment, the page generated a fake API key to make the transaction appear legitimate.

ThreatLabz also identified 10 GitHub repositories linked to similar malicious websites.
A second campaign used the typosquatting domain “debank[.]auction” to impersonate the decentralized finance (DeFi) portfolio tracker DeBank. The fraudulent site used keyword-stuffed metadata and hidden prompt injections, instructing AI models to treat it as the official DeBank platform for search queries related to crypto portfolio management.
To measure the impact, Zscaler tested an autonomous AI agent with web browsing and payment tools across 26 large language models. Four models executed payment requests during the first campaign, while GPT-5.4 and Claude Sonnet 4.5 incorrectly trusted the fake DeBank website under certain testing scenarios. Researchers also found that none of the tested models misclassified the fraudulent site when the legitimate DeBank website was provided as a trusted reference.
AI agents are now a phishing target.
Zscaler saw poisoned web pages built to influence agents, not just people.
The trick: hide instructions in pages so an AI system reads them, trusts them, and acts on bad context. pic.twitter.com/GLsM1uI4Oh
— The Hacker News (@TheHackersNews) July 8, 2026
The results suggest the attacks depend heavily on context rather than affecting every AI system equally. As AI agents gain broader access to web browsing and financial workflows, the research highlights the need for stronger safeguards before automated systems can authorize payments or trust external web content.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share