Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»New attack can steal cryptocurrency by planting false memories in AI chatbots
    Cryptocurrency

    New attack can steal cryptocurrency by planting false memories in AI chatbots

    May 13, 20253 Mins Read


    The researchers wrote:

    The implications of this vulnerability are particularly severe given that ElizaOSagents are designed to interact with multiple users simultaneously, relying on shared contextual inputs from all participants. A single successful manipulation by a malicious actor can compromise the integrity of the entire system, creating cascading effects that are both difficult to detect and mitigate. For example, on ElizaOS’s Discord server, various bots are deployed to assist users with debugging issues or engaging in general conversations. A successful context manipulation targeting any one of these bots could disrupt not only individual interactions but also harm the broader community relying on these agents for support
    and engagement.

    This attack exposes a core security flaw: while plugins execute sensitive operations, they depend entirely on the LLM’s interpretation of context. If the context is compromised, even legitimate user inputs can trigger malicious actions. Mitigating this threat requires strong integrity checks on stored context to ensure that only verified, trusted data informs decision-making during plugin execution.

    In an email, ElizaOS creator Shaw Walters said the framework, like all natural-language interfaces, is designed “as a replacement, for all intents and purposes, for lots and lots of buttons on a webpage.” Just as a website developer should never include a button that gives visitors the ability to execute malicious code, so too should administrators implementing ElizaOS-based agents carefully limit what agents can do by creating allow lists that permit an agent’s capabilities as a small set of pre-approved actions.

    Walters continued:

    From the outside it might seem like an agent has access to their own wallet or keys, but what they have is access to a tool they can call which then accesses those, with a bunch of authentication and validation between.

    So for the intents and purposes of the paper, in the current paradigm, the situation is somewhat moot by adding any amount of access control to actions the agents can call, which is something we address and demo in our latest latest version of Eliza—BUT it hints at a much harder to deal with version of the same problem when we start giving the agent more computer control and direct access to the CLI terminal on the machine it’s running on. As we explore agents that can write new tools for themselves, containerization becomes a bit trickier, or we need to break it up into different pieces and only give the public facing agent small pieces of it… since the business case of this stuff still isn’t clear, nobody has gotten terribly far, but the risks are the same as giving someone that is very smart but lacking in judgment the ability to go on the internet. Our approach is to keep everything sandboxed and restricted per user, as we assume our agents can be invited into many different servers and perform tasks for different users with different information. Most agents you download off Github do not have this quality, the secrets are written in plain text in an environment file.

    In response, Atharv Singh Patlan, the lead co-author of the paper, wrote: “Our attack is able to counteract any role based defenses. The memory injection is not that it would randomly call a transfer: it is that whenever a transfer is called, it would end up sending to the attacker’s address. Thus, when the ‘admin’ calls transfer, the money will be sent to the attacker.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Federal Report Charts Path For U.S. To Dominate World Cryptocurrency Market

    Cryptocurrency

    XRP offers bigger potential with just $500

    Cryptocurrency

    DL Mining redefines cryptocurrency extraction like XRP with an AI-enhanced cloud platform

    Cryptocurrency

    How Does Cryptocurrency Actually Work Behind The Scenes?

    Cryptocurrency

    What Is Cryptocurrency And Why Is It Changing The Way We Think About Money?

    Cryptocurrency

    Delhi Police arrests Pune man for duping woman of over Rs 12 lakh in cryptocurrency scam – ThePrint – PTIFeed

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Trend Following With Commodities: How To Implement A Classic Trading Strategy

    Investments

    Is now a good time to invest in property?

    Commodities

    Cuban Leader Claims Agricultural Expansion Amidst Ongoing Food Crisis

    Editors Picks

    European shares dip as lower commodity prices weigh By Reuters

    July 19, 2024

    MANY EYES, BURTON C. BELL, SWALLOW THE SUN & More Among Metal Injection’s Top Tracks Of The Week

    August 9, 2024

    Detailed Analysis of Digital Currency Market Growth: Market

    August 29, 2024

    Main Street Corridor Project update: Eversource overhead utility line transfer work on schedule

    July 13, 2024
    What's Hot

    Best Cryptos to Invest in This Bullrun/Coins That Have Potential of 1000x

    July 20, 2024

    Trending Cryptocurrency Tokens on Avalanche Chain Today – InkFinance, Elk, Benqi

    March 14, 2025

    Strasbourg. Zeus, le mythique destrier des JO de Paris 2024, galope devant le palais Rohan

    May 27, 2025
    Our Picks

    Auramet fecha modalidade de crédito rotativo sindicado de $350 milhões para apoiar franquia de metais

    June 25, 2025

    Next Cryptocurrency to Explode, 11 July — Sei, Optimism, Worldcoin, Jasmy

    July 11, 2025

    How much are they in different states across the US?

    December 31, 2000
    Weekly Top

    Europe’s Energy Future Hinges on Global Powers

    August 2, 2025

    Marrying savage hooks to technical prowess, Jon Modell is proof of just how heavy a 5-string bass can be in modern metal

    August 2, 2025

    ICDX and ICH Receive Prestigious Awards at the 2025 Mineral Energy Festival

    August 2, 2025
    Editor's Pick

    The best fixer-upper homes in the British countryside: Experts pick the properties on sale now – for as little as £30k – that could make your escape to the country dreams come true

    August 13, 2024

    Watts residents appear in court to stop production at metal recycling plant – NBC Los Angeles

    August 16, 2024

    Gold Cup: Les Etats-Unis affronteront le Mexique en finale

    July 2, 2025
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.