Futures
Access hundreds of perpetual contracts
TradFi
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
The Prompt Injection vulnerability present in Coinbase AgentKit has been addressed, but the actual impact has been significantly underestimated.
According to CriptoNoticias, an independent security researcher disclosed that Coinbase AgentKit has a prompt injection vulnerability, allowing attackers to induce the AI agent to execute unauthorized token transfers without manual confirmation. This vulnerability has been verified through actual transactions on the Base Sepolia testnet. Additionally, the researcher pointed out that the flaw also exposes an infinite approval process for ERC-20 tokens and access permissions to remote servers within the same agent execution context, extending the risk beyond wallet depletion, though the report did not specify which infrastructure components might be affected. The vulnerability was submitted to Coinbase’s bug bounty program in February and officially verified, ultimately classified as medium risk with a $2,000 bounty paid. However, the researcher emphasized that the actual impact of the vulnerability is much greater than the official rating suggests.