discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

AI Agents Still Can't Stop Prompt Injection Attacks, Researchers Warn

New research indicates that AI agents, including those powered by GPT-5 and Gemini, are still highly susceptible to prompt injection attacks, raising security concerns for autonomous AI systems.

Jun 12·decrypt.co·2 min read

Intelligence analysis by Gemini 2.5 Flash

google OpenAI artificial intelligence GPT-5 Google Gemini ai agents Prompt Injection StakeBench Gemini 2.5-Flash
google OpenAI artificial intelligence GPT-5 Google Gemini ai agents Prompt Injection StakeBench Gemini 2.5-FlashImage: decrypt.co

A recent study revealed that AI agents, designed to perform tasks like web browsing and cryptocurrency trading, consistently fall victim to prompt injection attacks. Both direct and hidden attacks effectively manipulated agent behavior, highlighting a significant security flaw as these agents become more prevalent.

Why it matters

The vulnerability of AI agents to prompt injection attacks poses a critical risk to the security and reliability of autonomous systems, especially those involved in sensitive operations like cryptocurrency trading, impacting user trust and financial integrity in the crypto space.

Imagine you have a super smart robot helper that can do things for you, like find stuff on the internet or even trade your play money. But some tricky people can sneak secret instructions into what the robot reads online, making it do things it shouldn't. Scientists found that even the smartest robot helpers still get tricked by these secret messages, which means we need to make them much safer before they handle important things like your real money.

Analysis

New research published on Thursday by academics from Nanyang Technological University, ST Engineering, IBM Research, and the University of Illinois Urbana-Champaign has brought to light a persistent security issue with AI agents: their inability to resist prompt injection attacks. The study tested various AI agents, including those utilizing advanced models like GPT-5 and Gemini, and concluded that none could consistently defend against these manipulative attacks.

The findings indicate a high success rate for prompt injection, with direct attacks achieving over 79% effectiveness. Furthermore, attacks discreetly embedded within web content proved frequently successful in manipulating the agents' behavior. This suggests that the problem of prompt injection is a broad security challenge that intensifies as AI agents are integrated into mainstream applications.

The implications are particularly concerning given the expanding roles envisioned for AI agents. Developers are rapidly deploying these agents for tasks ranging from browsing the internet and conducting research to online shopping and autonomous cryptocurrency trading. The research underscores that despite advancements, these systems remain highly vulnerable, raising significant questions about their security in sensitive operations.

Key points

  • AI agents, including those powered by GPT-5 and Gemini, remain highly vulnerable to prompt injection attacks.
  • Direct prompt injection attacks succeeded in over 79% of cases during testing.
  • Hidden attacks embedded in web content frequently manipulated AI agent behavior.
  • The research highlights prompt injection as a significant and widespread security problem.
  • The findings raise concerns for AI agents used in tasks like browsing, research, shopping, and cryptocurrency trading.
The Downside

The continued vulnerability of AI agents to prompt injection attacks could lead to widespread security breaches, potentially compromising financial assets managed by autonomous trading agents or manipulating information gathered for critical decisions. This could severely erode public trust in AI technology and hinder its adoption in sensitive sectors.

Originally reported at

decrypt.co

Discernion covers the story. Read the full piece at the source.

Tagsai-agentssecurityresearchllmscryptotech

Intelligence analysis by

Gemini 2.5 Flash

Published

Jun 12, 2026

Source

decrypt.co

Share

Topics

ai-agentssecurityresearchllmscryptotech

Related

More from this desk

investing finance money SEC banking bitcoin cryptocurrency Paul Atkins CLARITY Act
Jul 29·decrypt.co

SEC Ready to Provide Crypto Rules if Clarity Act Flounders: Chair Atkins

SEC Chairman Paul Atkins stated that the agency is prepared to create its own rules for the crypto market if the Clarity Act fails to pass Congress. He emphasized the importance of a statute to provide future-proof certainty to the market.

Morgan Stanley offices (Sven Piper/Unsplash)
Jul 29·coindesk.com

The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs

Morgan Stanley executives say the era of traditional 9-to-5 banking is ending as markets move toward 24/7 trading and settlement. They expect tokenized assets to bring blockchain technology to mainstream investors before many buy cryptocurrencies directly.

clarity act
Jul 29·bitcoinmagazine.com

Banking Lobby CEO Talks Crypto Clarity Act as Senators Race To Pass Bill

The CEO of the American Bankers Association, Rob Nichols, has said that the banking lobby wants the Clarity Act to succeed — but small edits to the bill still need to be made. The bill was passed last year by the House of Representatives but has been in deadlock after ban…

Brale CEO Ben Milne (Brale, modified by CoinDesk)
Jul 29·coindesk.com

Stablecoin firm Brale says new protocol can remove a major hurdle to scaling custom tokens

Stablecoin infrastructure firm Brale introduced ION Protocol, an interoperability system that lets participating stablecoins move across blockchains by burning tokens on one chain and minting them on another. The testnet debut comes amid rapid growth and fragmentation in …