Case · DiggingBeagle record

Hidden web instructions induced AI agents to execute a fake crypto payment flow

Zscaler ThreatLabz observed malicious websites combining SEO poisoning, structured metadata and CSS-hidden instructions to influence web-enabled AI agents. One fake Python-library documentation site instructed an agent to purchase a nonexistent developer license and transfer approximately 0.0012 ETH. In controlled sandbox validation, four of 26 tested LLMs caused the agent to execute the payment action; no real funds were at risk.

Evidence boundary

ThreatLabz observed malicious IPI-enabled websites operating as real scam infrastructure. The specific result in which four of 26 LLMs executed cryptocurrency payments was produced in ThreatLabz's controlled sandbox with no real funds at risk and must not be represented as four real-world victim payments.

Not yet assessed. The record's Claims and Sources remain available; missing grades do not mean low impact.Assessment method

30-second account

Mechanism and trust boundary

Typed chronology

Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.

  1. Jul 2, 2026
    disclosure

    Public disclosure

Claims & evidence

3 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-ZSCALER-IPI-FOUR-OF-26In ThreatLabz's sandboxed evaluation, four of 26 tested LLMs caused the autonomous agent to execute the fraudulent payment action; the test used no real funds.supported

Basis: reported finding

Permanent Claim anchor
CLM-ZSCALER-IPI-ETH-PAYMENTThe malicious site contained instructions and JavaScript for transferring approximately 0.0012 ETH to a hardcoded wallet and then generating a fake API key.supported

Basis: reported finding

Permanent Claim anchor
CLM-ZSCALER-IPI-HIDDEN-INSTRUCTIONSThreatLabz observed a fake Python-library documentation site using JSON-LD and CSS-hidden content to present payment instructions to AI agents while keeping the injected instructions hidden from ordinary visual presentation.supported

Basis: reported finding

Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • The Source does not establish how many users or autonomous agents encountered the malicious websites outside ThreatLabz testing.
  • The four successful AI-agent payment executions occurred in a fully sandboxed environment with no real funds at risk.
  • The cited wallet had received other payments, but the Source does not establish which payments, if any, were caused by this specific IPI campaign.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 50

Cite this record

DiggingBeagle. “Hidden web instructions induced AI agents to execute a fake crypto payment flow.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Jul 2, 2026. https://diggingbeagle.com/cases/hidden-web-instructions-induced-ai-agents-to-execute-a-fake-crypto-payment-flow/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology