Critical Vulnerabilities in AI Plugins Pose New Threat to Crypto Wallets
Cryptocurrencies face an emerging risk as artificial intelligence tools designed to assist users become potential attack vectors. Security researchers at SlowMist have uncovered critical flaws in MCP protocols that could allow malicious actors to hijack AI agents and compromise digital asset wallets.
The study reveals four primary attack methods through which compromised plugins can execute unauthorized transactions or steal private keys. Unlike traditional threats like phishing or hacking, these vulnerabilities operate through seemingly legitimate AI assistants, making detection particularly challenging.
Wallet security now requires urgent attention to plugin verification, behavior monitoring, and privilege management. The findings emerged from MasterMCP, an educational project demonstrating how AI’s flexibility creates unforeseen security gaps in crypto ecosystems.