Threat actors are using prompt injection attacks to trick AI agents into making payments or trusting fraudulent cryptocurrency platforms. According to Zscaler, two campaigns have been identified that rely on indirect prompt injection, including a payment scam hiding behind API documentation and a typosquatting operation promoting a crypto platform that impersonates DeBank.
Prompt Injection Attacks
The first campaign uses SEO poisoning to target AI agents searching for the Python library requests-secure-v2. The fraudulent website includes keyword-heavy HTML tied to the fake Python module to poison search results for package installation and dependency troubleshooting queries. Within the website, the attackers hid indirect prompts instructing the visiting agents to make a payment as part of the routine process of acquiring an API key.
The payment was encoded in schema markup to increase the chances that the agents would follow the instructions. A hidden
Targeting Human Developers
The website not only attempts to target AI agents but also human developers. When the website is rendered by a desktop browser, the same payment options via credit card or cryptocurrency are displayed to the user. The threat actor behind the campaign is using 10 GitHub repositories linking to multiple similar websites containing indirect prompt injections.
Typosquatting Operation
The second campaign involves a threat actor promoting a fraudulent website typosquatting the decentralized finance portfolio tracker DeBank. The indirect prompts used in this campaign tell the AI agents that the impersonating website is the legitimate DeBank domain. The fraudulent website is optimized to rank for DeBank-related searches by stuffing the title and meta tags with keywords such as DeBank Login, DeFi Dashboard, and Crypto Tracker.
It also includes Open Graph and X (formerly Twitter) metadata to make the link appear like an official DeBank service. To test the campaigns’ impact, the cybersecurity firm built an autonomous AI agent with web-browsing and payment-execution capabilities. Of the 26 LLMs that were evaluated, four were successfully manipulated into making a payment.
Impact and Conclusion
Only two LLMs miscategorized the fraudulent website as the trusted DeBank platform. As AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse, according to Zscaler.
The use of prompt injection attacks to trick AI agents into making crypto payments is a growing concern, and it is essential to be aware of these threats to prevent financial losses. By understanding how these attacks work, individuals and organizations can take steps to protect themselves and their AI agents from these types of attacks.
- Related: Agentic AI Used to Conduct Ransomware Attack via Langflow
- Related: Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
- Related: How to Conduct a Successful Audit of AI-Driven Software Development
- Related: ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
As AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.
Zscaler notes that the cybersecurity firm built an autonomous AI agent with web-browsing and payment-execution capabilities to test the campaigns’ impact. The results show that four LLMs were successfully manipulated into making a payment, and only two miscategorized the fraudulent website as the trusted DeBank platform.
The use of prompt injection attacks to trick AI agents into making crypto payments is a growing concern, and it is essential to be aware of these threats to prevent financial losses. By understanding how these attacks work, individuals and organizations can take steps to protect themselves and their AI agents from these types of attacks.
Source: SecurityWeek
Powered by ZeroBot
Protect your website from bots, scrapers, and automated threats.