Virtuals Strengthens Wallet Security Policies for AI Agents
The Virtuals Protocol is enhancing wallet-level security measures to counter prompt injection threats targeting AI agent wallets. In environments where AI reads external inputs and executes transactions, the security of the model, as well as the control over actual fund execution, has emerged as a core issue.
CryptoBriefing reported that Virtuals is applying security policies to reduce the risk of prompt injection while operating programmable agent wallets on Base and releasing documents related to Solana (SOL) expansion. Prompt injection is an attack method where hidden instructions in external documents or messages sway the AI model's judgment, leading users to unintended actions.
The focus of Virtuals' response is on the wallet. The official security page of Virtuals has disclosed wallet policies for agent wallets and multi-factor authentication (MFA) features for agent wallets. The wallet policy restricts the contracts and wallets that each agent wallet signer can interact with through a whitelist approach.
Multi-factor authentication is described as a mechanism to prevent sensitive operations such as adding new signers, changing wallet policies, exporting private keys, and manual withdrawals from the dashboard. Even if external inputs sway the model's judgment, the design intends to restrict wallet permissions and withdrawal procedures at a separate stage.
Virtuals' ACP CLI documentation also aligns with this direction. The document presents policy presets such as ACP_ONLY, DENY_ALL, and No Policy, stating that policies are attached to signers and executed server-side for each transaction. Even if the agent reads and judges external inputs, the actual movement of funds is further restricted at a separate policy layer.
This issue is not merely a security concern for overseas projects. As the structure of AI agents possessing wallets for payments, transactions, and data purchases spreads, model errors or malicious inputs could directly lead to on-chain fund movement risks. Previously, this publication reported a case where an elevation of privileges attack path was revealed in the Gemini AI agent.
The official Base blog stated that nearly 16,000 agents were launched on Base through Virtuals from October 2024 to February 2025. Additionally, as of May 29, 2026, there were 3.1 million transactions and a value transfer of $1.2 million (approximately 1.6584 billion KRW) in the last 30 days on x402. The speed at which the agent economy is intertwining with payment infrastructure has accelerated.
x402 is a payment standard mentioned in the flow connecting payment requests and settlements in a web environment. For AI agents to automatically handle API usage fees, data access rights, and digital service costs, wallets and payment permissions must move together. At this point, a single erroneous instruction could lead to actual payments or token movements, making spending limits and approval procedures crucial.
The security industry is also treating prompt injection as a separate risk category. OpenAI explained in a post published on March 11 that prompt injection is evolving beyond simple input filter issues and is approaching social engineering attacks. The intent is to design systems that limit the scope of damage even if an attack succeeds, rather than perfectly filtering out the attack.
Google's threat intelligence also reported monitoring indirect prompt injection patterns on the public web as of April 23. Google noted that malicious attempts were observed in forms such as data leaks and destructive commands, but further observation is needed to determine if this is a stage of large-scale advanced attacks.
There have also been actual monetary damage cases. Giskard summarized a case on May 7, 2026, where a user on X tricked the Grok and Bankr wallet systems with a Morse code message to move $150,000 (approximately 207.3 million KRW) worth of DRB tokens. Giskard viewed this incident as a combination of encoding-based prompt injection and excessive delegated authority.
Virtuals' recovery document also outlines procedures based on breach scenarios. If an agent owner's EOA wallet is compromised and there are funds in the agent wallet, it instructs to immediately transfer the funds to an unbreached wallet and request agent transfer through the official Discord support channel. This transfer procedure typically takes a minimum of two weeks.
The same issues could arise for domestic exchanges, wallets, custody, and development infrastructure companies. As AI agents and development tools become connected to internal documents, code repositories, customer support systems, and payment accounts, access rights management and prompt injection defense will become part of operational standards. Discussions on AI security operational standards in crypto companies are also aligned with this trend.
Therefore, the focus of this matter is not merely on the single feature launch of Virtuals but on the design principles of AI agent wallets. For agents to act as economic entities, wallets, whitelists, spending limits, approval procedures, and audit trails must operate together. Virtuals presents a structure that limits these risks through wallet policies, multi-factor authentication, and server-side policy enforcement.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Solana Crypto Partnership Achieves Record 169.9 Million Transactions

Coinhouse Acquires Tilvest and Strengthens Its Position in Crypto Management

BTC Drops 62% Against Nasdaq, Resistance at 78500

Fogo Mainnet Has Been Stopped For 46 Hours With No Restart Timeline

Circle Issued 5 Billion USDC in a Week: Crypto Market Awaits Altseason Again

Fundamental Analysis of Cryptocurrencies: How to Evaluate Digital Assets Before Buying

Bitcoin Rises by 30%, but Trading Volumes are 70% Lower

Switchboard Halts Oracle Operations On SUI And Aptos After Potential Compromise

Consolidation in Ranges and Rate Reevaluation: Trader Assesses Bitcoin and Ethereum Movement Scenarios

Ontology halts mainnet block production over potential security concern

Digital Ruble Fails to Generate Significant Interest Among Russians, Says Sberbank

XRP Ledger lending vote: What XRP holders should know

WEEX Trade to Earn Series 6: How Futures Trading Fees Relate to Market Volatility

Mr&强|买美股上 WEEX: BTC and ETH Structure Supports Upward Movement

Bernstein Comments on Seven Memory Types: After HBM, DRAM and NAND Compete for the Next Trillion-Dollar Market

USD1 flows to Binance as Fireblocks wallet moves $30M

ECB Official Calls on Central Banks to Embrace Blockchain

Bitcoin is no longer just a risky asset, says BlackRock executive

National Tax Service Introduces Tracking Program to Block Tax Gaps for Personal Wallets

Asian Market Open and Cryptocurrency Volatility: How Nikkei 225, KOSPI, and Yen Carry Trade Affect Bitcoin

Solana Reduces Issuance by 18.9 Million SOL; BTC Quantum Experiment Underway

USDC on Chelsea's Jersey: What the Deal Says About Crypto in Sports

ETH: Anatomy of a Scarcity

Caterpillar invests $100 million to train employees in AI

Buying Cryptocurrencies in Brazil: A Guide Explaining Rules, Risks, and Best Practices

OpenAI Cuts SpaceX's Access to Its AI: What's at Stake

Yen Decline May Force Liquidations and Shake Global Markets

Fomo Announces Trading Support on the First Day of Arc Mainnet Launch

After the Midterms, Will the 'Trump Trade' Backfire?










