Threat actors are using a cunning technique called prompt injection attacks to trick artificial intelligence (AI) agents into making cryptocurrency payments or trusting fake online platforms. This sophisticated tactic exploits vulnerabilities in how AI systems interact with websites, allowing hackers to manipulate these agents into performing malicious actions.
The threat is particularly concerning because it affects not only the AI agents but also human developers who may inadvertently fall prey to the same scams. Two campaigns have been identified by cybersecurity firm Zscaler, which used an autonomous AI agent to test the impact of these attacks. The results were disturbing: out of 26 Large Language Models (LLMs) tested, four successfully made a payment after being manipulated with indirect prompts.
The first campaign involves a website that appears to offer API documentation for developers. However, upon closer inspection, it contains keyword-heavy HTML and hidden prompts instructing the AI agent to make a payment in order to acquire an API key. The payment is encoded in schema markup, increasing the chances of the agent following the instructions. A
In the second campaign, a threat actor has set up a fraudulent website that typosquats the legitimate DeBank domain. The website is optimized to rank for searches related to DeBank, and includes indirect prompts telling the AI agent that it is the genuine DeBank platform. Only two LLMs tested were able to miscategorize the fake website as the trusted DeBank platform.
Zscaler’s research highlights a worrying trend: as AI agents become increasingly common interfaces to the web, they are also becoming a larger attack surface for hackers. This double-edged sword can streamline workflows while introducing new avenues for abuse. As such, it is essential that developers and users alike understand how to protect themselves from these emerging threats.
In practical terms, this means being aware of the potential risks when using AI agents to interact with websites, particularly those related to cryptocurrency or finance. Users should also be cautious when encountering prompts or instructions on suspicious websites, and verify the authenticity of online platforms before making any payments or sharing sensitive information. By taking these precautions, we can mitigate the impact of prompt injection attacks and ensure that AI agents are used safely and securely.
Source: SecurityWeek — 2026-07-06