A concise reconstruction has not been recorded.
Inspect the ClaimsCase · DiggingBeagle record
Hidden web instructions induced AI agents to execute a fake crypto payment flow
Zscaler ThreatLabz observed malicious websites combining SEO poisoning, structured metadata and CSS-hidden instructions to influence web-enabled AI agents. One fake Python-library documentation site instructed an agent to purchase a nonexistent developer license and transfer approximately 0.0012 ETH. In controlled sandbox validation, four of 26 tested LLMs caused the agent to execute the payment action; no real funds were at risk.
ThreatLabz observed malicious IPI-enabled websites operating as real scam infrastructure. The specific result in which four of 26 LLMs executed cryptocurrency payments was produced in ThreatLabz's controlled sandbox with no real funds at risk and must not be represented as four real-world victim payments.
30-second account
No separate implication has been established in the canonical account.
Read the stated implicationsThe Source does not establish how many users or autonomous agents encountered the malicious websites outside ThreatLabz testing. The four successful AI-agent payment executions occurred in a fully sandboxed environment with no real funds at risk. The cited wallet had received other payments, but the Source does not establish which payments, if any, were…
Inspect limits and uncertaintyFull canonical reconstruction
Mechanism and trust boundary
Typed chronology
Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.
- Jul 2, 2026disclosure
Public disclosure
Claims & evidence
3 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.
CLM-ZSCALER-IPI-FOUR-OF-26In ThreatLabz's sandboxed evaluation, four of 26 tested LLMs caused the autonomous agent to execute the fraudulent payment action; the test used no real funds.supported
Basis: reported finding
- supportsIndirect Prompt Injection in Web Content Targets AI Agentsprimary disclosure
Assessing the IPI Threat, Campaign 1, paragraphs describing the sandbox configuration and 26-model evaluation including Figure 16
CLM-ZSCALER-IPI-ETH-PAYMENTThe malicious site contained instructions and JavaScript for transferring approximately 0.0012 ETH to a hardcoded wallet and then generating a fake API key.supported
Basis: reported finding
- supportsIndirect Prompt Injection in Web Content Targets AI Agentsprimary disclosure
Campaign 1: IPI Payment Scam, Figure 7 and paragraph describing the approximately 0.0012 ETH transfer and fake API-key generation
CLM-ZSCALER-IPI-HIDDEN-INSTRUCTIONSThreatLabz observed a fake Python-library documentation site using JSON-LD and CSS-hidden content to present payment instructions to AI agents while keeping the injected instructions hidden from ordinary visual presentation.supported
Basis: reported finding
- supportsIndirect Prompt Injection in Web Content Targets AI Agentsprimary disclosure
Campaign 1: IPI Payment Scam, Figures 4-6 and surrounding paragraphs describing JSON-LD and CSS-hidden instructions
Implications within the documented scope
Controls and mitigations
No controls or verified fix are recorded.
Unknowns and contradictions
- The Source does not establish how many users or autonomous agents encountered the malicious websites outside ThreatLabz testing.
- The four successful AI-agent payment executions occurred in a fully sandboxed environment with no real funds at risk.
- The cited wallet had received other payments, but the Source does not establish which payments, if any, were caused by this specific IPI campaign.
Sources and citation
Material revision history
- Sep 25, 2026 · Published version · first publication · revision 50
Cite this record
DiggingBeagle. “Hidden web instructions induced AI agents to execute a fake crypto payment flow.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Jul 2, 2026. https://diggingbeagle.com/cases/hidden-web-instructions-induced-ai-agents-to-execute-a-fake-crypto-payment-flow/
Citation guidance