Virtuals Strengthens Wallet Security Policies for AI Agents
The Virtuals Protocol is enhancing wallet-level security measures to counter prompt injection threats targeting AI agent wallets. In environments where AI reads external inputs and executes transactions, the security of the model, as well as the control over actual fund execution, has emerged as a core issue.
CryptoBriefing reported that Virtuals is applying security policies to reduce the risk of prompt injection while operating programmable agent wallets on Base and releasing documents related to Solana (SOL) expansion. Prompt injection is an attack method where hidden instructions in external documents or messages sway the AI model's judgment, leading users to unintended actions.
The focus of Virtuals' response is on the wallet. The official security page of Virtuals has disclosed wallet policies for agent wallets and multi-factor authentication (MFA) features for agent wallets. The wallet policy restricts the contracts and wallets that each agent wallet signer can interact with through a whitelist approach.
Multi-factor authentication is described as a mechanism to prevent sensitive operations such as adding new signers, changing wallet policies, exporting private keys, and manual withdrawals from the dashboard. Even if external inputs sway the model's judgment, the design intends to restrict wallet permissions and withdrawal procedures at a separate stage.
Virtuals' ACP CLI documentation also aligns with this direction. The document presents policy presets such as ACP_ONLY, DENY_ALL, and No Policy, stating that policies are attached to signers and executed server-side for each transaction. Even if the agent reads and judges external inputs, the actual movement of funds is further restricted at a separate policy layer.
This issue is not merely a security concern for overseas projects. As the structure of AI agents possessing wallets for payments, transactions, and data purchases spreads, model errors or malicious inputs could directly lead to on-chain fund movement risks. Previously, this publication reported a case where an elevation of privileges attack path was revealed in the Gemini AI agent.
The official Base blog stated that nearly 16,000 agents were launched on Base through Virtuals from October 2024 to February 2025. Additionally, as of May 29, 2026, there were 3.1 million transactions and a value transfer of $1.2 million (approximately 1.6584 billion KRW) in the last 30 days on x402. The speed at which the agent economy is intertwining with payment infrastructure has accelerated.
x402 is a payment standard mentioned in the flow connecting payment requests and settlements in a web environment. For AI agents to automatically handle API usage fees, data access rights, and digital service costs, wallets and payment permissions must move together. At this point, a single erroneous instruction could lead to actual payments or token movements, making spending limits and approval procedures crucial.
The security industry is also treating prompt injection as a separate risk category. OpenAI explained in a post published on March 11 that prompt injection is evolving beyond simple input filter issues and is approaching social engineering attacks. The intent is to design systems that limit the scope of damage even if an attack succeeds, rather than perfectly filtering out the attack.
Google's threat intelligence also reported monitoring indirect prompt injection patterns on the public web as of April 23. Google noted that malicious attempts were observed in forms such as data leaks and destructive commands, but further observation is needed to determine if this is a stage of large-scale advanced attacks.
There have also been actual monetary damage cases. Giskard summarized a case on May 7, 2026, where a user on X tricked the Grok and Bankr wallet systems with a Morse code message to move $150,000 (approximately 207.3 million KRW) worth of DRB tokens. Giskard viewed this incident as a combination of encoding-based prompt injection and excessive delegated authority.
Virtuals' recovery document also outlines procedures based on breach scenarios. If an agent owner's EOA wallet is compromised and there are funds in the agent wallet, it instructs to immediately transfer the funds to an unbreached wallet and request agent transfer through the official Discord support channel. This transfer procedure typically takes a minimum of two weeks.
The same issues could arise for domestic exchanges, wallets, custody, and development infrastructure companies. As AI agents and development tools become connected to internal documents, code repositories, customer support systems, and payment accounts, access rights management and prompt injection defense will become part of operational standards. Discussions on AI security operational standards in crypto companies are also aligned with this trend.
Therefore, the focus of this matter is not merely on the single feature launch of Virtuals but on the design principles of AI agent wallets. For agents to act as economic entities, wallets, whitelists, spending limits, approval procedures, and audit trails must operate together. Virtuals presents a structure that limits these risks through wallet policies, multi-factor authentication, and server-side policy enforcement.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Circle Adds Support for USDC and EURC Transfers on Plasma

XAUUSD: Understanding and Trading the Gold/Dollar Pair in 2026

Apple TV+ Raises Price for the 4th Time: What's Behind It

Cedears: ETFs Replicating Soybeans and Corn to Be Added to the Market

Spot Trading on Decentralized Exchanges Reaches 13.6%, Sparking Debate on DeFi Governance

Federal Reserve Total Assets Reach $6.73 Trillion, Renewed Debate on Reserves

Beyond the rally: 4 Trends to watch this cycle

Ukraine and Romania Agree on Measures to Accelerate Shipping through the Sulina Canal

BIT Investment Opportunities Forum Held in Hong Kong, Discussing Next Phase of Market and Asset Allocation Opportunities

RLUSD Market Cap Surpasses $2 Billion as XRP Ledger Transition Advances, XRP ETF Trading Volume Hits Record High
![[Kang Ryun-ho's Crypto Zoom-In] The Advancement of the Regulatory Framework for Virtual Asset Businesses and Practical Responses](/public-static/20_9098579959.png?format=avif)
[Kang Ryun-ho's Crypto Zoom-In] The Advancement of the Regulatory Framework for Virtual Asset Businesses and Practical Responses

CCC exploit drains $117K after attacker targets BSC liquidity pool

Fed Balance Sheet at 21% of GDP: Central Banks Deflate, Liquidity Persists

Iran Sets Conditions and Demands Compensation to Reopen Hormuz Strait

Bitcoin Coinbase Premium Rises to Zero as Market Buying Weakens

What Does the 'Niche Market' of Gold Mean?

BTC Transfer from Kraken: 843 Bitcoins Leave the Exchange to Unknown Wallet

Mysterious $23 Million Bitcoin-Monero Swap: The Viral Video That Raises Questions

Encrypted Code Reveals $44 Million Transactions in a 'Cold Wallet' Linked to Cerimedo

Votorantim Exchanges Nexa for $1.3 Billion Stake in Boliden

The dollar takes a breather after the price fixing for bond payments linked to the exchange rate

Banking Processing in the New Reality: Digital Ruble and Cryptocurrencies for Foreign Trade

Bitcoin Profit and Loss Indicator Shows Weak Bullish Signal

Train Delays of Over 17 Hours for Ukrzaliznytsia Due to Russian Shelling

How one small BTC transfer exposed the fine print behind Trump’s ‘never sell’ strategic Bitcoin reserve

Pedestrian Traffic Changes Near Bessarabsky Square in Kyiv

DEBIT Airdrop Guide: How to Share 50,000 USDT Rewards on WEEX

Coincheck Completes Registration for Electronic Payment Services, Becomes Second Company in Japan

HYPE whale adds $24M as a16z link remains unverified








