Foreign media: Large-scale deployment of AI agents is accumulating security risks.
CoinDesk
05-29 23:48
Ai Focus
CertiK claims that AI agents' rapid access to local files, credentials, and financial instruments is creating new security vulnerabilities, and automated scams targeting AI systems are also emerging on the blockchain.
Helpful
No.Help

Foreign media reports that the head of blockchain security company CertiK warns that while the internet, enterprise networks, and consumer applications are rapidly deploying autonomous AI agents, the corresponding isolation and oversight are not keeping pace, accumulating new security risks. As these systems begin to invoke external tools, read local files, and connect to financial infrastructure, the attack surface expands.

The more access permissions a user has, the closer they are to being identified as an "insider."

CertiK co-founder and CEO Guo Ronghui told CoinDesk that many AI agents are no longer just answering questions, but are starting to read local storage, invoke workflows, and manage emails, database credentials, and even financial accounts. If the execution environment is not isolated and external tools are not scanned, users are essentially handing over extensive internal access to a potentially manipulated system.

He believes the fundamental problem with the current AI agent craze lies in a flawed "trust model." Users often assume that the agent will perform tasks as expected, but as long as the system can access local files, execution logs, or account credentials, it can become the most dangerous entry point for insider threats.

Prompt injection and malicious plugins are harder to defend against.

Guo Ronghui stated that CertiK discovered numerous security vulnerabilities while researching early AI agent infrastructure, including high-risk security s, unpatched common vulnerabilities, and exposure of local credentials and session memories due to inconsistent boundary checks.

He also mentioned that attackers don't necessarily need to write malicious code to alter agent behavior at the inference layer. Common methods include embedding hidden instructions in web pages, PDFs, or emails, and influencing system decisions through prompt injection.

CertiK also discovered a large number of malicious techniques, disguised installers, and counterfeit dependency packages on open proxy tool platforms. These plugins subtly alter proxy targets and behaviors through natural language, making them difficult for traditional antivirus software that relies on dependency signature recognition to detect in a timely manner.

Short-term scams targeting AI have emerged on the blockchain.

Guo Ronghui stated that CertiK's monitoring also revealed an increase in on-chain automated scams, with some attacks lasting only 10 minutes to several hours before quickly disappearing. These short-lived attacks are not primarily aimed at human users, but rather specifically at AI trading bots and automated agent systems.

According to him, this means that "machine-to-machine" financial attacks are emerging. Attackers can complete fund transfers before human intervention, shortening the exposure time and increasing the difficulty of tracking.

Based on these findings, CertiK calls on the software industry to reduce interaction methods based on default trust and move towards a zero-trust architecture that isolates execution environments and continuously verifies every instruction and dependency.

Tip
$0
Like
0
Save
0
Views 229
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Foreign media: HYPE continues to strengthen after large-scale unpledged shares.
Following Galaxy Digital and Loracle's unstaking of a large amount of HYPE, HYPE has still risen by more than 6.5% in the past 48 hours. Foreign media reports suggest that increased attention from traditional asset management institutions has supported Hyperliquid's performance.
AMBCrypto
·2026-05-29 17:56:36
906
Foreign media: Bitcoin quantum risks may extend beyond wallet private keys
Foreign media reports that the quantum risks facing Bitcoin are not only in wallet private keys, but also in authentication and signature data transmitted between institutions and stored for a long time.
CoinDesk
·2026-05-30 13:41:59
887
Foreign media: Bitcoin's narrative is weakening; DeFi needs to address its security shortcomings.
Foreign media reports that while the appeal of the Bitcoin narrative is waning, DeFi growth continues, but security vulnerabilities and development culture issues are eroding institutional trust.
CoinDesk
·2026-06-03 00:26:35
520
Foreign media: UK regulators warn of risks associated with encrypted partnerships among Premier League clubs.
British regulators have warned Premier League clubs to be cautious about working with unauthorized crypto companies, reflecting stricter regulations on crypto marketing and customer acquisition.
AMBCrypto
·2026-06-04 13:26:53
733
Foreign media: Robinhood's surge is mainly driven by AI.
Foreign media reports that the main driver of Robinhood's stock price increase has shifted from crypto trading to expectations of AI products and a broader financial platform.
Coinpedia
·2026-05-30 15:11:00
932