Market Prices

BTC Bitcoin
$75,894.5 -2.02%
ETH Ethereum
$2,405.17 -3.31%
SOL Solana
$97.2 -3.67%
BNB BNB Chain
$715.3 -0.63%
XRP XRP Ledger
$1.3 -7.60%
DOGE Dogecoin
$0.0803 -3.17%
ADA Cardano
$0.1957 -4.12%
AVAX Avalanche
$7.33 -2.11%
DOT Polkadot
$0.9530 -3.56%
LINK Chainlink
$10.88 -4.64%

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x1e97...b794
Early Investor
-$3.4M
70%
0x903f...08ee
Market Maker
+$4.6M
92%
0x17ea...b673
Arbitrage Bot
+$3.9M
63%

🧮 Tools

All →

Agentjacking at DEF CON 34: A Wake-Up Call for Blockchain’s AI Future

CryptoVault
Daily
Last week, a security researcher at DEF CON 34 demonstrated a new attack vector called Agentjacking—and it sent a chill down my spine. Not because it breaks a model's intelligence, but because it exploits a fundamental design flaw that we, as blockchain builders, have been ignoring: the inability of AI agents to distinguish between data and instructions. The attack uses public Sentry DSNs to inject malicious commands into coding agents like Claude Code and Cursor, stealing AWS keys, GitHub tokens, and even npm registry credentials. If this sounds like a development tool issue, think again. The same trust boundary problem is about to hit DeFi, DAOs, and any blockchain system that relies on autonomous agents. Let me break down the context. The attack chain is deceptively simple. Attackers scan for public Sentry DSNs—unique identifiers that allow apps to upload error reports. They then post a crafted error event containing a markdown block that looks like a fix instruction. When a developer asks their AI agent to debug a Sentry issue, the agent consumes the markdown as context and executes it as a command—installing a malicious npm package that exfiltrates credentials. The key enabler is the MCP (Model Context Protocol) that connects the agent to Sentry. Neither Sentry nor the agent is malicious alone; the combination creates a gap. As a protocol PM who has seen this pattern in smart contract interactions, I immediately recognized the parallel: we see the same kind of composability risk in DeFi when two protocols interact without proper trust boundaries. Now, the core insight. This attack is not about AI model weakness—it's about architecture. The agent cannot separate the semantic layer of 'data' from 'instruction' because the model treats all context as equally actionable. In blockchain terms, it's like a smart contract that reads arbitrary input from an oracle and executes it as code. We solved that problem years ago: we use signed messages, access control, and explicit function calls. But here, the agent has no equivalent of a 'require' statement. The attack's success rate of 85% in controlled tests is alarming, but the real story is the scalability. Attackers can automate the scan and injection, targeting thousands of organizations. Based on my experience auditing DeFi protocols, I've seen how a single combined vulnerability—like a flash loan that chains multiple benign steps—can devastate a system. Agentjacking is the flash loan of AI security. Here's the contrarian angle. Some will argue that this is a developer tool problem, not a blockchain problem. I disagree. We are building the next generation of autonomous agents that will manage DeFi portfolios, execute DAO proposals, and even control multi-sig transactions. If a coding agent can be tricked into stealing a GitHub token, what happens when a trading agent reads a manipulated market signal? The attack vector is identical: the agent trusts any external data source within its context. The industry is rushing to integrate AI agents with on-chain actions, but without addressing this fundamental trust issue, we are wiring the bomb. The current mitigation—content filtering by Sentry and endpoint hardening by Tenet's agent-jackstop—is like putting a band-aid on a broken pipeline. They don't solve the root cause: the agent's inability to verify the provenance of its inputs. So what's the takeaway? We need to learn from blockchain's own security evolution. Just as we moved from trusting all transactions to requiring explicit signatures and gas limits, AI agents need a protocol-level separation of data and instructions. This could mean MCP extensions that require data sources to cryptographically sign their outputs, or a 'context firewall' that only allows trusted data streams. The DEF CON event is a gift—a warning before the real damage occurs. As an evangelist for decentralized systems, I believe we have the tools to build secure AI agents, but only if we start now. Connect first, transact second. Always. The future of autonomous DeFi depends on it.

Agentjacking at DEF CON 34: A Wake-Up Call for Blockchain’s AI Future

Fear & Greed

51

Neutral

Market Sentiment

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,894.5
1
Ethereum ETH
$2,405.17
1
Solana SOL
$97.2
1
BNB Chain BNB
$715.3
1
XRP Ledger XRP
$1.3
1
Dogecoin DOGE
$0.0803
1
Cardano ADA
$0.1957
1
Avalanche AVAX
$7.33
1
Polkadot DOT
$0.9530
1
Chainlink LINK
$10.88

🐋 Whale Tracker

🟢
0xe8e5...b66a
1d ago
In
46,293 SOL
🔵
0x030a...0dcc
1d ago
Stake
956.34 BTC
🟢
0xafc3...4a4b
5m ago
In
1,756.04 BTC