Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»New attack can steal cryptocurrency by planting false memories in AI chatbots
    Cryptocurrency

    New attack can steal cryptocurrency by planting false memories in AI chatbots

    May 13, 20253 Mins Read


    The researchers wrote:

    The implications of this vulnerability are particularly severe given that ElizaOSagents are designed to interact with multiple users simultaneously, relying on shared contextual inputs from all participants. A single successful manipulation by a malicious actor can compromise the integrity of the entire system, creating cascading effects that are both difficult to detect and mitigate. For example, on ElizaOS’s Discord server, various bots are deployed to assist users with debugging issues or engaging in general conversations. A successful context manipulation targeting any one of these bots could disrupt not only individual interactions but also harm the broader community relying on these agents for support
    and engagement.

    This attack exposes a core security flaw: while plugins execute sensitive operations, they depend entirely on the LLM’s interpretation of context. If the context is compromised, even legitimate user inputs can trigger malicious actions. Mitigating this threat requires strong integrity checks on stored context to ensure that only verified, trusted data informs decision-making during plugin execution.

    In an email, ElizaOS creator Shaw Walters said the framework, like all natural-language interfaces, is designed “as a replacement, for all intents and purposes, for lots and lots of buttons on a webpage.” Just as a website developer should never include a button that gives visitors the ability to execute malicious code, so too should administrators implementing ElizaOS-based agents carefully limit what agents can do by creating allow lists that permit an agent’s capabilities as a small set of pre-approved actions.

    Walters continued:

    From the outside it might seem like an agent has access to their own wallet or keys, but what they have is access to a tool they can call which then accesses those, with a bunch of authentication and validation between.

    So for the intents and purposes of the paper, in the current paradigm, the situation is somewhat moot by adding any amount of access control to actions the agents can call, which is something we address and demo in our latest latest version of Eliza—BUT it hints at a much harder to deal with version of the same problem when we start giving the agent more computer control and direct access to the CLI terminal on the machine it’s running on. As we explore agents that can write new tools for themselves, containerization becomes a bit trickier, or we need to break it up into different pieces and only give the public facing agent small pieces of it… since the business case of this stuff still isn’t clear, nobody has gotten terribly far, but the risks are the same as giving someone that is very smart but lacking in judgment the ability to go on the internet. Our approach is to keep everything sandboxed and restricted per user, as we assume our agents can be invited into many different servers and perform tasks for different users with different information. Most agents you download off Github do not have this quality, the secrets are written in plain text in an environment file.

    In response, Atharv Singh Patlan, the lead co-author of the paper, wrote: “Our attack is able to counteract any role based defenses. The memory injection is not that it would randomly call a transfer: it is that whenever a transfer is called, it would end up sending to the attacker’s address. Thus, when the ‘admin’ calls transfer, the money will be sent to the attacker.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Will Budget 2026 provide clarity on cryptocurrency taxation, simplify compliance?

    Cryptocurrency

    PayPal and NCA Survey Shows Rising Merchant Adoption of Cryptocurrency Payments

    Cryptocurrency

    Coinbase adverts banned in UK for suggesting crypto could ease cost of living crisis | Cryptocurrencies

    Cryptocurrency

    Guide for Indian Players 2026

    Cryptocurrency

    A Guide for Indian Gaming Fans

    Cryptocurrency

    Japan Prepares to Launch Cryptocurrency ETFs by 2028 as Institutional Adoption Accelerates

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    How to Heal in Metal Gear Solid Delta: Snake Eater – Metal Gear Solid Delta: Snake Eater Guide

    Precious Metal

    Wheaton Precious Metals Posts Record Revenue In Q2 2025 As Cash Outflow Hits

    Commodities

    les géants français du metal en tournée dans toute la France… et des places encore disponibles !

    Editors Picks

    Is There an Opportunity in South32 After Global Commodities Surge in 2025?

    October 9, 2025

    Secret criminal past of ‘Traveller King’ who was buried in a ‘six-figure, solid gold’ coffin

    August 24, 2025

    All the ways pensions are about to change and how they will affect you

    December 24, 2025

    Qonto se laisse séduire par le cloud de S3NS

    April 1, 2025
    What's Hot

    Bullet For My Valentine: the story behind The Poison

    August 17, 2024

    Salt Investments lève 7 millions de dollars singapouriens grâce à un placement d’actions

    June 1, 2025

    From Industry to the Living Room: Metal Furniture in Interior Architecture

    January 19, 2026
    Our Picks

    How Platforms Must Evolve For The Next Generation

    November 25, 2025

    Klarna : le guide vers une nouvelle vague d’IPO fintech -Le 24 mars 2025 à 15:35

    March 24, 2025

    Mariposa Safe Families Commodities for Hope Program Accepting Donations for Local Families in Need

    October 26, 2025
    Weekly Top

    Here’s How The Biggest Players Moved The Commercial Real Estate Market In 2025

    January 28, 2026

    Property tech firm extends footprint with takeover

    January 28, 2026

    Understanding Above Par Bonds: Definition and Market Impact

    January 28, 2026
    Editor's Pick

    A Fan-Owned Soccer Team In Hawaii Is Looking To Surf A Bitcoin Wave

    August 5, 2024

    Which Snacks Would Antony Mackie & More Twisted Metal Stars Risk Their Lives to Find?

    August 7, 2025

    3 Energy Stocks With Juicy Dividend Yields

    June 27, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.