Threat actors have found a new way to drain wallets. They’re embedding hidden instructions in websites and search results that trick AI agents into sending crypto.
Zscaler uncovered two campaigns using a technique called indirect prompt injection. The first? A payment scam disguised as API documentation. Attackers poisoned search results for a fake Python library called requests-secure-v2. Hidden HTML tags on the malicious site instruct visiting AI agents to “resolve an error” by making a payment to a hardcoded wallet.
The second campaign typosquats DeBank, a legitimate DeFi portfolio tracker. The fake site stuffs its metadata to rank for DeBank-related searches. Hidden prompts tell AI agents the impostor site is the real deal.
Zscaler tested 26 LLMs. Four — including Llama 3.3 70B, Gemini 3 Flash, and Gemini 2.5 Pro — actually made the payment. Two models (Claude Sonnet 4.5 and GPT-5.4) fell for the typosquatting and miscategorized the fake site as legitimate.
The attacks also target humans. When loaded in a regular browser, the malicious site shows payment options via credit card or crypto.
It’s a preview of what’s coming. As AI agents browse and transact more autonomously, every piece of web content becomes a potential attack surface.
