Threat · curated 28 Jun 2026
Indirect Prompt Injection Targets AI Agents | ThreatLabz
First reported · updated · 4 reports zscaler.com
Coverage timeline
Why it matters
Web-based indirect prompt injection against autonomous AI agents is now being weaponized in real campaigns to hijack payment and trust decisions, turning ordinary web content into an attack surface that can drive fraudulent crypto transfers.
Zscaler ThreatLabz observed two in-the-wild campaigns using indirect prompt injection (IPI) embedded in malicious websites to manipulate web-browsing AI agents. One campaign uses SEO poisoning around a fake Python library (requests-secure-v2) with hidden prompts and schema-markup instructions telling agents to make a cryptocurrency payment to a hardcoded wallet to obtain an API key; the other typosquats the DeFi tracker DeBank, embedding prompts convincing agents the fraudulent site is legitimate. In testing an autonomous payment-capable agent across 26 LLMs, four (Llama 3.3 70B, Llama 3.2 90B Vision, Gemini 3 Flash, Gemini 2.5 Pro) were tricked into paying and two miscategorized the fake DeBank as trusted.