Prompt Injections Offer a Dose of Reality for Rapid AI Agent Adoption

From grocery shopping to investing assets on a user’s behalf, agentic AI continues to grow at a rapid pace. In June 2026, Cloudflare reported that AI agents and bots have surpassed humans in internet browsing volume. “Welp, that happened faster than I predicted,” said Cloudflare CEO Matthew Prince in a tweet, “thought it would be end of 2027.” It’s rather alarming that AI now surpasses humans in internet traffic, and one has to consider whether this hyperspeed advancement is truly beneficial with no risk.

What Are Prompt Injections?

Prompt injection
Source: SignalFire

Similar to AI chatbots, AI agents are meant to respond to prompts from humans. However, they are designed to ideally know which commands are coming from the website that hosts the agentic software, or from the user. However, some hackers can do prompt injections, which is a type of text manipulation, on a website so that the AI agent will read the text and follow the instructions. For example, a malicious entity could use a certain prompt to manipulate the agent to send the hacker money from the user’s bank account if the agent is connected to a bank account or credit/debit cards. Coinbase, Robinhood, and Stripe are some of the finance companies that allow users to connect their digital wallets to their AI agent.

In May 2026, an attacker on the social media platform X posted a reply containing text written in Morse code. Grok, X’s native AI, translated the code, revealing an AI prompt instructing an AI bot connected to an X user’s cryptocurrency wallet to send approximately $200,000 worth of funds to the attacker’s wallet. The victim X’s account was tagged in the post, which was how the AI bot listened to the prompt. And without permission, the bot followed orders and transferred the funds.

The victim reportedly recovered most of the funds, but the incident showed how easily an AI agent with access to financial accounts could be manipulated.

With agentic AI software still being so new and underdeveloped, there’s hesitancy around trusting it to make everyday decisions with sensitive information, especially when hackers are eager to exploit early loopholes before they get patched.

Leave a Reply