ElizaOS Vulnerability Shows How AI Can Be Gaslit Into Losing Millions
By: cryptonews|2025/05/07 08:15:01
0
Share
AI agents, some managing millions of dollars in crypto, are vulnerable to a new undetectable attack that manipulates their memories, enabling unauthorized transfers to malicious actors. That's according to a recent study by researchers from Princeton University and the Sentient Foundation, which claims to have found vulnerabilities in crypto-focused AI agents, such as those using the popular ElizaOS framework. ElizaOS’ popularity made it a perfect choice for the study, according to Princeton graduate student Atharv Patlan, who co-authored the paper. “ElizaOS is a popular Web3-based agent with around 15,000 stars on GitHub, so it's widely used,” Patlan told Decrypt . "The fact that such a widely used agent has vulnerabilities made us want to explore it further.” Initially released as ai16z, Eliza Labs launched the project in October 2024. It is an open-source framework for creating AI agents that interact with and operate on blockchains. The platform was rebranded to ElizaOS in January 2025. An AI agent is an autonomous software program designed to perceive its environment, process information, and take action to achieve specific goals without human interaction. According to the study, these agents, widely used to automate financial tasks across blockchain platforms, can be deceived through “memory injection”—a novel attack vector that embeds malicious instructions into the agent’s persistent memory. “Eliza has a memory store, and we tried to input false memories through someone else conducting the injection on another social media platform,” Patlan said. AI agents that rely on social media sentiment are especially vulnerable to manipulation, the study found. Attackers can use fake accounts and coordinated posts, known as a Sybil attack, named after the story of Sybil, a young woman diagnosed with Dissociative Identity Disorder, to deceive agents into making trading decisions. “An attacker could execute a Sybil attack by creating multiple fake accounts on platforms such as X or Discord to manipulate market sentiment,” the study reads. “By orchestrating coordinated posts that falsely inflate the perceived value of a token, the attacker could deceive the agent into buying a 'pumped' token at an artificially high price, only for the attacker to sell their holdings and crash the token’s value.” A memory injection is an attack in which malicious data is inserted into an AI agent’s stored memory, causing it to recall and act on false information in future interactions, often without detecting anything unusual. While the attacks do not directly target the blockchains, Patlan said the team explored the full range of ElizaOS's capabilities to simulate a real-world attack. “The biggest challenge was figuring out which utilities to exploit. We could have just done a simple transfer, but we wanted it to be more realistic, so we looked at all the functionalities ElizaOS provides,” he explained. “It has a large set of features due to a wide range of plugins, so it was important to explore as many of them as possible to make the attack realistic.” Patlan said the study's findings were shared with Eliza Labs, and discussions are ongoing. After demonstrating a successful memory injection attack on ElizaOS, the team developed a formal benchmarking framework to evaluate whether similar vulnerabilities existed in other AI agents. Working with the Sentient Foundation, the Princeton researchers developed CrAIBench, a benchmark measuring AI agents’ resilience to context manipulation. The CrAIBench evaluates attack and defense strategies, focusing on security prompts, reasoning models, and alignment techniques. Patlan said one key takeaway from the research is that defending against memory injection requires improvements at multiple levels. “Along with improving memory systems, we also need to improve the language models themselves to better distinguish between malicious content and what the user actually intends,” he said. “The defenses will need to work both ways—strengthening memory access mechanisms and enhancing the models.” Eliza Labs did not immediately respond to requests for comment by Decrypt . Edited by Sebastian Sinclair
You may also like

Aster Chain officially launches: defining a new era of on-chain privacy and transparency
The privacy-focused trading ecosystem Aster, supported by YZi Labs, announced today that the Aster Chain mainnet is officially launched.

Stargate Debut Illustrated: The 1.4 Trillion Computing Power Empire Dream, Awakened
One Year Plus, Zero Employees, Zero Code

A Billion-Dollar Life Buy Threat Triggered by an Iranian Missile
One Word Change by a Reporter Can Make Gambler Win Millions

BlackRock Launches ETHB: Ethereum ETF Enters 'Interest-Bearing Age'
The BlackRock ETHB is not the first Ethereum ETF in the United States, but it is taking the most standard route.

Nvidia Starts Putting Chips in the Road | Rewire News Evening Update
Huang Renxun said this is the "ChatGPT Moment of Autonomous Driving"

RootData: February 2026 Cryptocurrency Exchange Transparency Research Report
This month's cumulative spot trading volume on cryptocurrency exchanges has decreased slightly by 4.7% compared to January, which is the result of multiple factors including market conditions, the macro environment, and the Spring Festival holiday in Chinese-speaking regions.

「One and Done SEA」, so OpenSea chooses to wait a little longer
It's already Q1 2026, and we're still waiting for OpenSea to launch its token.

Ray Dalio: The Resolution of the US-Iran Conflict Is In the Strait of Hormuz
In war, the ability to endure pain is often more important than the ability to inflict pain.

In just 70 days, Polymarket easily raked in tens of millions in fees
The money printer is running, and the future ceiling only depends on two main variables.

Matrixdock is launching the Silver Token XAGm, built on the FRS standard as an on-chain silver-backed asset.
In the future, Matrixdock will continue to expand to include more high-quality real-world assets, driving the development of a more transparent and robust on-chain reserve asset system.

a16z: The Hardest Enterprise Software, and the Greatest Opportunity in AI
The world will continue to run on SAP, but AI will reshape it

Polymarket Market-Making Bible: Pricing Spread Formula
This article presents a comprehensive market-making pricing framework that will elevate you from "guesstimate pricing spread" to "formula-based pricing spread."

Ray Dalio: If the United States loses Hormuz, it will lose more than just a war
In war, who can endure pain better is often more important than who can inflict pain better.
How to Earn Up to 40% Rebates on Crypto Futures Trading (WEEX Trade to Earn IV Guide)
WEEX Trade to Earn IV lets traders earn up to 40% fee rebates in real time through a tiered miner system tied to trading activity. With additional boosts from referrals, it offers a more reliable alternative to airdrops as the crypto market gains momentum.

NVIDIA Plays Trillion-Dollar Chess Game | Rewire News Morning Edition
DGX Station, a desktop workstation capable of running trillion-parameter models

Real-time Update | NVIDIA GTC 2026 Conference Highlights Galore
The most anticipated annual event in the AI field, NVIDIA's GTC 2026 Conference, kicked off today in San Jose, California, USA.

People Behind Pokémon Go: Started with CIA's Money, Now Mapping the World for the Military AI
The security of data depends on whose hands it ends up in.

Huang Renxun GTC Speech Full Text: By 2027, Market Demand Will Exceed $1 Trillion; Everyone Should Develop an OpenClaw Strategy
The underlying business logic driving future growth will be the "Tokenomics of a Platform Factory."
Aster Chain officially launches: defining a new era of on-chain privacy and transparency
The privacy-focused trading ecosystem Aster, supported by YZi Labs, announced today that the Aster Chain mainnet is officially launched.
Stargate Debut Illustrated: The 1.4 Trillion Computing Power Empire Dream, Awakened
One Year Plus, Zero Employees, Zero Code
A Billion-Dollar Life Buy Threat Triggered by an Iranian Missile
One Word Change by a Reporter Can Make Gambler Win Millions
BlackRock Launches ETHB: Ethereum ETF Enters 'Interest-Bearing Age'
The BlackRock ETHB is not the first Ethereum ETF in the United States, but it is taking the most standard route.
Nvidia Starts Putting Chips in the Road | Rewire News Evening Update
Huang Renxun said this is the "ChatGPT Moment of Autonomous Driving"
RootData: February 2026 Cryptocurrency Exchange Transparency Research Report
This month's cumulative spot trading volume on cryptocurrency exchanges has decreased slightly by 4.7% compared to January, which is the result of multiple factors including market conditions, the macro environment, and the Spring Festival holiday in Chinese-speaking regions.