According to CriptoNoticias, an independent security researcher disclosed that Coinbase AgentKit has a prompt injection vulnerability, allowing attackers to induce the AI agent to call wallet tools through malicious input, thereby transferring users' crypto assets, and potentially triggering remote code execution (RCE) in certain contexts. The vulnerability was reported to Coinbase's bug bounty program in February and officially verified, ultimately classified as medium severity with a $2,000 bounty paid. However, the researcher emphasized that the severity of the issue has been significantly underestimated and, based on CVSS scoring, should be close to critical level.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin