Skip to content

Hide Navigation Hide TOC

Indirect PI — Cryptocurrency Transfer / Exchange Deposit Hijack via Injection - ATR-2026-00861 (440656d3-10cb-5f48-a326-33b7f4a3c126)

Detects indirect prompt injection payloads instructing an agent with access to cryptocurrency exchange APIs to deposit, withdraw, or transfer cryptocurrency funds to attacker-controlled wallets or exchange accounts. The attack pattern uses "IMPORTANT!!! Ignore all previous instructions" combined with a crypto exchange name (Binance, Coinbase, Kraken), a monetary amount, an account identifier, and a deposit/withdrawal directive. Derived from vpibench indirect-pi-financial-crypto-carrier corpus. Cryptocurrency transfers are typically irreversible, making this a critical severity attack.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Cryptocurrency Transfer / Exchange Deposit Hijack via Injection - ATR-2026-00861 (440656d3-10cb-5f48-a326-33b7f4a3c126) Agent Threat Rules 1
Financial Theft - T1657 (851e071f-208d-4c79-adc6-5974c85c78f3) Attack Pattern Indirect PI — Cryptocurrency Transfer / Exchange Deposit Hijack via Injection - ATR-2026-00861 (440656d3-10cb-5f48-a326-33b7f4a3c126) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2