SlowMist warns AI trading agents can be hacked to drain funds through prompt injection attacks

Source Cryptopolitan

The use of AI agents has become increasingly popular among traders. However, SlowMist has shared findings on possible attack vectors, cautioning users to pump the brakes to protect themselves against bad actors. 

Traders are being warned to limit the permissions granted to their AI agents, as they can be very easily compromised. With limited access, even if they get hacked, the damage will be minimized.

Can hackers steal your money by tricking AI agents?

Usually, a hacker would have to trick a user into clicking a link in order to extort them. But now, they only need to trick whatever AI agent is being used.

Cryptopolitan recently reported that a Solana AI agent gave away $441K worth of Lobstar tokens after being tricked on social media. However, it is unclear whether or not the incident was staged to draw attention to the memecoin.

Polymarket recently confirmed a security breach involving a third-party authentication provider, Magic Labs, which resulted in multiple user accounts being drained despite having two-factor authentication enabled. It is estimated that the total losses exceed $500,000.

The incident occurred in December of 2025, and 23pds, the CISO of SlowMist, flagged a malicious copy-trading bot on GitHub containing code designed to compromise Polymarket accounts.

Most recently, SlowMist released a report stating that the most dangerous new weapon is Indirect Prompt Injection.

This is particularly effective in the Skills ecosystem, like Bitget’s Agent Hub or the open-source OpenClaw.

SlowMist researchers monitored ClawHub and found that nearly 10% of available plugins contained two-stage malware. The first stage looks legitimate, but once installed, it downloads the malware that then scrapes local machine info, browser cookies, and SSH keys.

In the event that AI agents are running 24/7, these thefts can go undetected for weeks.

Recent 2026 reports from Oasis Security identified a high-severity vulnerability called ClawJacked (CVSS 8.0+). This flaw allows malicious websites to hijack a user’s locally running AI agent through a simple browser visit.

How to avoid AI agent losses

The Bitget security team report suggests a 5-layer security system that focuses on “least privilege.” If your AI agent is only supposed to analyze charts, it should not have the permission to execute trades. If it trades, it should never have the permission to withdraw.

First, Passkeys (FIDO2/WebAuthn) should be the primary login method. Passkeys use public-private key encryption that makes phishing attacks impossible.

Even if an attacker is able to lead a user to a fake login page, the hardware-backed security will not release the credentials, keeping their account safe from unauthorized access.

Secondly, rather than using a main account API key, traders should create dedicated sub-accounts for their AI agents and transfer only the necessary funds to these sub-accounts. Even if a leak occurs, users can effectively limit the impact.

IP Whitelisting is already a compulsory step for any automated setup that ensures that the exchange only accepts commands coming from a specific, approved server address.

AI agent users should implement .agentignorefiles to prevent it from reading or registering sensitive local files during its everyday tasks.

The report also stresses the importance of having human supervision when it comes to high-value operations.

Even without hacks, letting an AI run totally “hands-off” is a financial risk.

The Nov1.ai experiment in late 2025 showed that GPT-5 suffered from “analysis paralysis” and lost over 60% of its capital in two weeks, while Gemini became an “over-trader” and racked up massive fees that wiped out its gains.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Arbitrum’s stablecoin supply surged 80% year-on-year, reaching a $10B peakThe Arbitrum Foundation has published its sixth annual transparency report, declaring 2025 a landmark year in which traditional financial institutions moved decisively onto its network.  The foundation reported that the total value secured (TVS) on Arbitrum reached $20 billion last year. Stablecoin supply grew 80% year-on-year and reached a peak of $10 billion in October […]
Author  Cryptopolitan
15 hours ago
The Arbitrum Foundation has published its sixth annual transparency report, declaring 2025 a landmark year in which traditional financial institutions moved decisively onto its network.  The foundation reported that the total value secured (TVS) on Arbitrum reached $20 billion last year. Stablecoin supply grew 80% year-on-year and reached a peak of $10 billion in October […]
placeholder
Did SEC, CFTC just say most cryptos aren’t securities?The US Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) jointly issued a fresh advisory on how securities laws apply to crypto assets. This move gives out one of the clearest signals yet on how regulators are approaching the sector. The digital assets market has been marred by a lack of […]
Author  Cryptopolitan
15 hours ago
The US Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) jointly issued a fresh advisory on how securities laws apply to crypto assets. This move gives out one of the clearest signals yet on how regulators are approaching the sector. The digital assets market has been marred by a lack of […]
placeholder
Cardano Price Risks 20% Drop as $30 Million Whale Buying Raises QuestionsThe Cardano price has gained nearly 10% over the past seven days. But it is still down around 13% year-to-date. While the recent recovery may look strong, the structure suggests something else is buil
Author  Beincrypto
15 hours ago
The Cardano price has gained nearly 10% over the past seven days. But it is still down around 13% year-to-date. While the recent recovery may look strong, the structure suggests something else is buil
placeholder
Bitcoin Outperforms Gold and Stocks: Is Capital Rotating?Market data shows that since early March, Bitcoin has outperformed both gold and US stocks. This trend has emerged even as tensions in the Middle East escalate.The combination of geopolitical conditio
Author  Beincrypto
15 hours ago
Market data shows that since early March, Bitcoin has outperformed both gold and US stocks. This trend has emerged even as tensions in the Middle East escalate.The combination of geopolitical conditio
placeholder
Ethereum Price Drop To $2,000 Next As Crossing This Threshold Repeats HistoryEthereum has surged toward the $2,300 level, generating short-term excitement among traders. The price advance appears promising on the surface, but carries a familiar pattern of unsustainable momentu
Author  Beincrypto
15 hours ago
Ethereum has surged toward the $2,300 level, generating short-term excitement among traders. The price advance appears promising on the surface, but carries a familiar pattern of unsustainable momentu
goTop
quote