Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»New attack can steal cryptocurrency by planting false memories in AI chatbots
    Cryptocurrency

    New attack can steal cryptocurrency by planting false memories in AI chatbots

    May 13, 20253 Mins Read


    The researchers wrote:

    The implications of this vulnerability are particularly severe given that ElizaOSagents are designed to interact with multiple users simultaneously, relying on shared contextual inputs from all participants. A single successful manipulation by a malicious actor can compromise the integrity of the entire system, creating cascading effects that are both difficult to detect and mitigate. For example, on ElizaOS’s Discord server, various bots are deployed to assist users with debugging issues or engaging in general conversations. A successful context manipulation targeting any one of these bots could disrupt not only individual interactions but also harm the broader community relying on these agents for support
    and engagement.

    This attack exposes a core security flaw: while plugins execute sensitive operations, they depend entirely on the LLM’s interpretation of context. If the context is compromised, even legitimate user inputs can trigger malicious actions. Mitigating this threat requires strong integrity checks on stored context to ensure that only verified, trusted data informs decision-making during plugin execution.

    In an email, ElizaOS creator Shaw Walters said the framework, like all natural-language interfaces, is designed “as a replacement, for all intents and purposes, for lots and lots of buttons on a webpage.” Just as a website developer should never include a button that gives visitors the ability to execute malicious code, so too should administrators implementing ElizaOS-based agents carefully limit what agents can do by creating allow lists that permit an agent’s capabilities as a small set of pre-approved actions.

    Walters continued:

    From the outside it might seem like an agent has access to their own wallet or keys, but what they have is access to a tool they can call which then accesses those, with a bunch of authentication and validation between.

    So for the intents and purposes of the paper, in the current paradigm, the situation is somewhat moot by adding any amount of access control to actions the agents can call, which is something we address and demo in our latest latest version of Eliza—BUT it hints at a much harder to deal with version of the same problem when we start giving the agent more computer control and direct access to the CLI terminal on the machine it’s running on. As we explore agents that can write new tools for themselves, containerization becomes a bit trickier, or we need to break it up into different pieces and only give the public facing agent small pieces of it… since the business case of this stuff still isn’t clear, nobody has gotten terribly far, but the risks are the same as giving someone that is very smart but lacking in judgment the ability to go on the internet. Our approach is to keep everything sandboxed and restricted per user, as we assume our agents can be invited into many different servers and perform tasks for different users with different information. Most agents you download off Github do not have this quality, the secrets are written in plain text in an environment file.

    In response, Atharv Singh Patlan, the lead co-author of the paper, wrote: “Our attack is able to counteract any role based defenses. The memory injection is not that it would randomly call a transfer: it is that whenever a transfer is called, it would end up sending to the attacker’s address. Thus, when the ‘admin’ calls transfer, the money will be sent to the attacker.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    How Trump got close to crypto before pardoning the Binance CEO

    Cryptocurrency

    Beyond Bitcoin: Understanding Altcoins And The Future Of Digital Currency

    Cryptocurrency

    Morocco Strengthens Its Position Among Leading Cryptocurrency

    Cryptocurrency

    Key suspect Qian Zhimin pleads guilty in major cryptocurrency money laundering case under China-UK probe: police

    Cryptocurrency

    European Central Bank Sets 2029 Launch Date for Digital Euro

    Cryptocurrency

    Are Central Bank Digital Currencies (CBDCs) The Future Of Money?

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Stock Market

    Türkiye advances autonomous drone technology for maritime use

    Commodities

    Global partnerships in focus as Punjab Agricultural University officials visit US varsities

    Fintech

    Côte d’Ivoire-AIP/ La Fintech Wave et la BAL lancent à Abidjan un tournoi de Basket-ball pour détecter des jeunes talents – AIP

    Editors Picks

    Exclusive: BiggerPockets nets majority investment from TCG

    August 7, 2024

    TUNGSTEN Premiere New Single & Music Video “Lullaby” : Metal-Rules.com

    August 26, 2024

    New Cryptocurrency Releases, Listings, & Presales Today – Rivalz Network, Sixpack Token, RZUSD

    February 22, 2025

    Tower Real Estate Investment Trust publie ses résultats pour le deuxième trimestre et le semestre clos le 31 décembre 2024 -Le 20 janvier 2025 à 13:31

    January 20, 2025
    What's Hot

    Bus driver impaled by metal rod, still steers passengers to safety

    September 17, 2025

    Camden Property Trust : Stifel Nicolaus réitère son opinion positive sur le titre

    May 2, 2025

    Otsego County Fair continues to build on agricultural legacy

    August 16, 2024
    Our Picks

    When is the US election? Everything you need to know about the 2024 race

    July 21, 2024

    Floki Becomes Official Cryptocurrency Partner of Nottingham Forest F.C.

    August 15, 2024

    BNY Investments get game face on for City AM Triathlon Challenge

    August 6, 2025
    Weekly Top

    UPI Goes Global, Fintech Hits A Wall

    October 31, 2025

    My Kitchen Rules star Anthony Michael Mu accused of beating a woman with a metal spatula and throwing a burger at her head

    October 31, 2025

    Go global with investments or lose out: Top experts share simple secrets to world investing

    October 31, 2025
    Editor's Pick

    Here’s where property taxes rose the most in the last few years

    May 6, 2025

    Landlord’s brutal response after tenant refuses to vacate property amid eviction: ‘My house my rules’

    October 20, 2025

    King County honors courthouse dog in retirement ceremony

    October 21, 2025
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.