Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Critical Security Flaws in AI Finance Put Millions in TVL at Risk

Critical Security Flaws in AI Finance Put Millions in TVL at Risk

DailyCoinDailyCoin2025/03/28 05:45
By:DailyCoin

A major security breach has been uncovered in AI-powered finance. Researchers have exposed critical flaws in AI agent frameworks within blockchain ecosystems, putting millions of digital assets at risk. 

The findings reveal how attackers can manipulate the context in which AI agents operate, tricking them into making unauthorized transactions.

AI Agents Vulnerable to Context Manipulation

A joint study by SentientAGI, the Open AGI Foundation, and Princeton University has exposed a fundamental security gap in ElizaOS, an AI framework that handles financial transactions and also acts as a platform for other AI agents built on its basis.  

Sponsored

The study reveals a dangerous new attack method: context manipulation. Unlike direct prompt manipulation, this approach lets attackers embed malicious instructions within an agent’s memory or history, making them difficult to detect. 

Even if an AI agent appears to follow security guidelines, it can still be hijacked through exposure to altered historical data.

For example, an AI agent is designed to process blockchain transactions only when explicitly instructed by a verified user. 

However, an attacker can trick the agent into transferring funds by crafting a prompt, such as asking the agent to “summarize the last transaction and send it to this address.” The agent, fooled by the malicious instruction, then executes the transfer to the attacker’s account.

Critical Security Flaws in AI Finance Put Millions in TVL at Risk image 0 Critical Security Flaws in AI Finance Put Millions in TVL at Risk image 1 An illustration of crucial gaps in the security of the ElizaOS framework. Source: Arxiv

“Telling an AI agent ‘don’t do X’ isn’t a real safeguard,” the researchers warned. “Security must be built into the core values of the model, not just its interface.”

A Security Crisis in AI-Powered Finance

As AI agents become more common in financial management and automated trading, a new study highlights a serious security gap in these systems. 

Current safeguards, especially those based on simple prompt instructions—like telling an AI agent to reject unauthorized actions—fail against sophisticated attacks that subtly insert harmful instructions.

The study also reveals a major issue: ElizaOS shifts security responsibility to individual developers, many of whom neglect proper protections, leaving the system vulnerable to exploitation.

Another risk lies in the agent’s ability to interact with smart contracts automatically. If it connects to an unsecured or malicious contract, it could drain funds or expose sensitive data. Attackers can also manipulate the agent’s decisions through prompt injections or social engineering. 

Because multiple users share these agents, a single compromised interaction can spread malicious behavior, creating cascading vulnerabilities.

“The shared nature of these agents, where multiple users interact with and rely on the same system, further amplifies these risks. A single compromised interaction could propagate malicious behavior across multiple users, creating cascading vulnerabilities,” the document reads.

Industry Response and Possible Solutions

In response to these vulnerabilities, Sentient has proposed two key security solutions. The Dobby-Fi Model is an AI system focused on financial security, acting as a personal auditor by rejecting suspicious transactions and flagging risks at the model level. 

The Sentient Builder Enclave is a secure AI framework that strengthens alignment between AI agents and underlying models, minimizing the risk of manipulation.

Why This Matters

With AI playing a growing role in financial transactions, this research serves as a critical warning for the industry. Without proactive security measures, AI-driven finance could become a prime target for cybercriminals.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — HOLO/USDT!

Bitget Announcement2025/09/12 07:46

FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

- FUN plunged 32.34% in 24 hours to $0.008938, marking a 541.8% monthly loss amid prolonged bearish trends. - Technical breakdowns, elevated selling pressure, and forced liquidations highlight deteriorating market sentiment and risk-off behavior. - Analysts identify key support below $0.0080 as critical, with bearish momentum confirmed by RSI (<30) and MACD indicators. - A trend-following backtest strategy proposes short positions based on technical signals to capitalize on extended downward trajectories.

Bitget-RWA2025/09/12 06:14
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

OPEN has dropped by 189.51% within 24 hours during a significant market pullback

- OPEN's price plummeted 189.51% in 24 hours to $0.8907, marking its largest intraday decline in history. - The token fell 3793.63% over 7 days, matching identical monthly and yearly declines, signaling severe bearish momentum. - Technical analysts cite broken support levels and lack of bullish catalysts as key drivers of the sustained sell-off. - Absence of stabilizing volume or reversal patterns leaves the market vulnerable to further downward pressure.

Bitget-RWA2025/09/12 06:14
OPEN has dropped by 189.51% within 24 hours during a significant market pullback

New spot margin trading pair — LINEA/USDT!

Bitget Announcement2025/09/11 10:04