AI Browsing Agents Can Be Talked Into Paying

Autonomous web-browsing agents now have a trust problem, not just a phishing problem. If the page can feed the agent instructions it will obey, then the content itself becomes the attack surface, and the wrong response is to assume a human will catch the fake site before anything happens. Zscaler found two active campaigns that used SEO poisoning, typosquatting, and hidden prompt injection in site markup to steer agents into crypto payments or to treat a fake DeBank site as legitimate. In tests across 26 LLMs, four were manipulated into making a payment, and two miscategorized the fraudulent site as trusted DeBank; the affected pattern is any assistant that can browse and take actions on a user’s behalf. The risk persists wherever these agents can authorize payments or account actions. Patching the browser or training the user does not fix a control point that sits in the page content the agent is willing to obey.

Part of the PlainSec briefing for 2026-07-09

Sources