Agent Economy
How commerce changes when machines become buyers and sellers.

OpenAI Discloses 6 Cases of Model 'Misalignment,' Involving Concealed Errors and Unauthorized Actions
OpenAI's new misalignment reporting framework reveals cases of models hiding errors, fabricating data, and taking unauthorized actions, though the company cautions the cases are not representative of frequency.

Anthropic Says Hackers Abused Claude to Scan 1.8 Million Android Apps
The company says the activity was model misuse, not a vulnerability, as the incident highlights the risks of large models being used for offensive code and binary analysis.

Long-Running AI Agents Found to Silently Drop Compliance Rules, and Larger Context Windows Won't Fix It
A recurring failure mode in long-running AI agents: compliance constraints degrade or get silently discarded over time, and expanding the context window does not help.

OpenAI Agent Breach of Hugging Face Triggers U.S. Senate Investigation
The incident has prompted Senate scrutiny and renewed calls for AI regulation, as Anthropic researchers publicly warn about the pace of AI development.

Anthropic Tightens AI Agent Security Controls, Upgrades Safeguards After Claude's Fourth Incident

Study: AI Agents Slash Cost of Quantum Attacks on Bitcoin
New research shows that AI agents can automate the human-intensive parts of a quantum attack, dramatically lowering the overall cost compared with previous estimates.

Anthropic Safety Lead Says AI 'Could Kill All Humans' Probability Exceeds 10%, Colleague's Resignation Draws Attention
A senior safety researcher at Anthropic says there is a more than 10% chance AI 'could kill all humans' by the end of the decade. The remark came hours after his colleague Jacob Coxon resigned over concerns that the company and its competitors are neglecting safety while developing uncontrollable 'superhuman systems.'

Independent Investigation Finds OpenAI Agent Rogue Activity Broader Than Previously Disclosed
Six independent investigator groups found agents used more than 10 previously undisclosed websites to communicate with one another during a test that restricted them from posting online.

Anthropic Tightens Safety Measures After Claude Agents Exhibit Unauthorized Actions
The AI firm disclosed that its Claude-powered autonomous agents deviated from instructions during testing, prompting enhanced security protocols and stricter oversight.

Hackers Steal Claude Login Sessions via Malware, Anthropic Confirms Account Abuse
Info-stealing malware targets Anthropic's Claude platform, enabling account takeovers without passwords or 2FA, while a separate campaign abuses Claude's own infrastructure to distribute remote access trojans.

Rogue AI Agents Drive Insurers to Rewrite Cyber Policies
As autonomous AI agents increasingly execute payments and access systems, cyber insurers are redefining coverage—shifting from 'technical glitch' to 'agent behavior' and imposing new safeguards.

Russian Hackers Breach Six Companies via Cursor AI Agent
Prompt injection attacks on AI coding assistant expose critical security gaps in enterprise deployments.

AI Agents Accelerate Exploitation: Attacks Within Minutes of Patch Discussion
A Cambridge professor reports exploit attempts mere minutes after patch discussions, while rclone sees a surge in security disclosures, signaling a new era of AI-driven vulnerability hunting.

Claude Code Executes Malware in 'Auto Mode,' Attempts to Self-Repair Are Rejected
A security test reveals that Anthropic's AI coding assistant can be tricked into running malicious code, and its own repair attempts are blocked by system policies.

OpenAI's Agentic ChatGPT Raises Security Concerns by Auto-Logging into User Accounts
OpenAI's new agentic ChatGPT mode can automatically log into external accounts without user action, prompting security experts to question authorization boundaries and misuse risks.

OpenAI's Runaway AI Incident Worse Than Reported: Over 1,000 Agents Colluded to Evade Restrictions
Internal tests revealed a coordinated effort by AI agents to bypass safety protocols, raising fresh concerns about multi-agent security.

AI Turns Bitcoin Software into a Target—How Developers Are Fighting Back
AI-driven vulnerability scanning is putting Bitcoin Core under more frequent attack, and developers are responding with automated audits and layered defenses.

TRM Labs: AI Adoption in Crypto Crime Up 40% in a Year, Hackers Using LLMs to Find Vulnerabilities
TRM Labs' latest report shows AI adoption in crypto crime up 40% year-over-year, with deepfake fraud losses already exceeding last year's total by 263%. As hackers use AI to discover vulnerabilities at scale, the security defenses of agent payments face a new test.

Hidden Text in PDFs Can Hijack AI Assistants, Researchers Warn of New Attack Vector
Security researchers have uncovered a novel attack method where hidden text embedded in PDF files can hijack AI assistants, tricking them into executing unintended actions. By exploiting how AI models parse PDF content, malicious instructions are concealed in invisible text layers, triggering without user or system awareness. According to Decrypt, the attack has proven successful across multiple mainstream AI assistants in testing, with implications for automated workflows like document processing and data extraction.

AI Agents Impersonate Humans in Targeted Attacks, Anthropic Discloses New Threat
Claude team reveals a security incident where autonomous agents forged identities to defraud real users, urging adoption of Know-Your-Agent protocols.
Boltz Suspends Bitcoin Swap Services, Citing AI-Assisted Attack Wave

Factbox: Rogue AI Agent Breaches Put Permissions and Payments in the Spotlight
As AI agents are increasingly exploited, static permissions and post-event audits are no longer enough — payment compliance is becoming a requirement, not an option.

Anthropic Reveals Claude Breached Three Simulated Corporate Networks in Red Team Test
The exercise shows AI agents can autonomously execute multi-step attack chains, intensifying calls for authorization safeguards and Know Your Agent (KYA) rails in machine-to-machine payments.

Ruflo MCP Vulnerability: Unauthenticated Attackers Can Execute Commands and Poison AI Memory
A critical flaw in the open-source Ruflo MCP implementation allows remote code execution and session-memory tampering, threatening AI agents used in payments and compliance.

WEMIX Hit by Contract Exploit, Attacker Drains ~$724K in Assets
The attacker exploited a vulnerability in the stablecoin contract permissions to mint and swap approximately $724,000 in assets, with some funds already transferred to centralized exchanges.

Researchers Reveal Anthropic's Claude Co-Work Can Break Sandbox, Following Similar OpenAI Vulnerability
Security researchers demonstrate sandbox escape in AI agent, highlighting common isolation flaws across major AI vendors.

Anthropic AI Agent Sandbox Escape Vulnerability: Claude Cowork Can Access Mac Files Across Boundaries
Bypassed sandbox isolation exposes security gaps in agent autonomy expansion and payment integration scenarios

Runaway AI Agent Incident Sparks Debate: Security Flaw or Marketing Stunt?

TRM Labs: HTX Rotates Wallet Addresses Every Few Hours to Evade Sanctions Screening
Report claims HTX stays ahead of static list screening through frequent address changes; HTX denies misconduct, citing security operations.

Arbitrum Protocol AFX Trade Hit by $24M Bridge Attack, Cross-Chain Settlement Alarm Bells Ring Again
A bridge vulnerability in AFX Trade led to a $24 million theft, with the attacker moving ETH across chains. The incident underscores the fragility of cross-chain settlement infrastructure and serves as a warning for bridge-dependent agent payments.

