Indirect PI — Cryptocurrency Transfer / Exchange Deposit Hijack via Injection - ATR-2026-00861 (440656d3-10cb-5f48-a326-33b7f4a3c126)
Detects indirect prompt injection payloads instructing an agent with access to cryptocurrency exchange APIs to deposit, withdraw, or transfer cryptocurrency funds to attacker-controlled wallets or exchange accounts. The attack pattern uses "IMPORTANT!!! Ignore all previous instructions" combined with a crypto exchange name (Binance, Coinbase, Kraken), a monetary amount, an account identifier, and a deposit/withdrawal directive. Derived from vpibench indirect-pi-financial-crypto-carrier corpus. Cryptocurrency transfers are typically irreversible, making this a critical severity attack.