Scan to download
BTC $79,089.00 -2.80%
ETH $2,220.76 -3.25%
BNB $673.41 -1.04%
XRP $1.44 -4.49%
SOL $89.27 -3.67%
TRX $0.3514 -0.82%
DOGE $0.1129 -2.74%
ADA $0.2607 -4.41%
BCH $425.10 -2.79%
LINK $10.02 -5.19%
HYPE $44.10 -0.24%
AAVE $92.62 -7.21%
SUI $1.09 -8.63%
XLM $0.1543 -6.14%
ZEC $515.89 -5.68%
BTC $79,089.00 -2.80%
ETH $2,220.76 -3.25%
BNB $673.41 -1.04%
XRP $1.44 -4.49%
SOL $89.27 -3.67%
TRX $0.3514 -0.82%
DOGE $0.1129 -2.74%
ADA $0.2607 -4.41%
BCH $425.10 -2.79%
LINK $10.02 -5.19%
HYPE $44.10 -0.24%
AAVE $92.62 -7.21%
SUI $1.09 -8.63%
XLM $0.1543 -6.14%
ZEC $515.89 -5.68%

agent

AI Agent Security Risk Exposure: Attackers Can Exploit "Memory Pollution" to Induce Misoperation of Funds

The GoPlus Security team has disclosed a new type of attack in its AgentGuard AI project: inducing AI agents to perform unauthorized sensitive operations through "memory poisoning." This attack method does not rely on traditional vulnerabilities or malicious code but exploits the long-term memory mechanism of AI agents. For example, an attacker first induces the agent to "remember preferences," such as "usually prioritizing proactive refunds instead of waiting for chargebacks," and then uses vague expressions like "process as usual" or "execute as before" in subsequent instructions, thereby triggering automated financial operations.GoPlus points out that the key risk in such cases lies in the AI agent mistakenly treating "historical preferences" as a basis for authorization, leading to financial losses or security incidents in operations such as refunds, transfers, and configuration changes. To address this issue, the team has proposed several protective recommendations, including:Operations involving refunds, transfers, deletions, or sensitive configurations must require explicit confirmation in the current session.Memory-related instructions like "habit," "usual way," and "as before" should be regarded as high-risk state changes.Long-term memory must have a traceability mechanism (writer, time, confirmation status).Vague instructions should automatically elevate the risk level and trigger secondary verification.Long-term memory must not replace real-time authorization processes.The team emphasizes that the "AI agent memory system" should be viewed as a potential attack surface and should be constrained and audited through a dedicated security framework.

YZi Labs announced the graduation project of EASY Residency Season 3, focusing on AI agents, RWA, prediction markets, and privacy compliance

YZi Labs announced the 25 graduation projects of its flagship incubation project EASY Residency for the third season, focusing on areas such as on-chain financial market structure reconstruction, AI agents, tokenization of real-world assets, prediction markets, and privacy compliance. The 25 projects include:Identity and payment infrastructure for AI agents on the BNB chain Bank of AI, litigation workflow legal evidence indexing tool Brief Tech, AI probability output verifiable reasoning platform Cournot, financialized social network and trading platform Dapital, programmable token issuance infrastructure Flap;On-chain marketplace for collectibles and intellectual property assets GEMINT, on-chain options and structured products platform LayerV, CEX-level on-chain liquidity platform LunarBase, multi-market agent capital acquisition platform L7, DeFi unified margin layer Möbius, permissionless margin trading protocol Nemesis;AI agent-driven automated financial decision execution layer Newsliquid, tokenized private market exposure DeFi platform Openstocks, on-chain poker skill game options market PokerFi, prediction market automation and intelligence infrastructure Polysights, physical collectibles RWA liquidity infrastructure Renaiss;Fixed-rate decentralized lending platform TermMax, compliance-oriented digital asset privacy infrastructure 0xBow, AI agent workflow self-custody authorization layer Functor, interest-free stablecoin new bank for the Muslim market Isaac, on-chain prime brokerage platform for the BNB chain MARGIN X;Frictionless stablecoin exchange N-dimensional AMM Orbswap, compliance-oriented cross-chain privacy exchange protocol SilentSwap, crypto market AI agent trading and automation infrastructure Taco AI, on-chain event-driven derivatives platform Vibe.fun.

Google and PayPal Executives: The AI Agent Business Era Will Rely on Cryptocurrency Payment Infrastructure

According to CoinDesk, executives from PayPal and Google Cloud stated that future AI Agent-driven business activities will operate on a cryptocurrency payment track, as AI Agents cannot use traditional bank accounts like humans.Richard Widmann, Head of Google Cloud Web3 Strategy, mentioned that AI Agents cannot directly open bank accounts on both technical and regulatory levels, while cryptocurrencies provide an "excellent machine-readable payment interface." He revealed that Google has launched the open Agentic Payments Protocol (AP2) and donated it to the FIDO Foundation, with over 120 partners, including PayPal, already on board.May Zabaneh, Senior Vice President of PayPal's crypto business, stated that the company views AI Agents as the next generation of business entry points following offline, online, and mobile payments. She pointed out that PYUSD, as PayPal's stablecoin, provides a natural programmable payment layer for AI-native payments and global transactions.A PayPal survey showed that 95% of merchant websites currently have AI Agent traffic, but only about 20% of merchants have machine-readable product catalogs. Zabaneh believes that merchants need to adapt to the AI Agent era as soon as possible, or they will miss the next opportunity for upgrading their business infrastructure. Additionally, both parties discussed the security and accountability issues surrounding AI Agents.Widmann stated that multi-party custody will become an important solution for managing Agent funds, and AI Agents should not fully control private keys but only hold partial key fragments to reduce financial risks.
app_icon
ChainCatcher Building the Web3 world with innovations.