← Back to KHAO

AI Agent · CertiK ·

Gu revealed that CertiK discovered hundreds of malicious skills, fake installers

2 min read

Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.

✓ KHAO Verified

CertiK co-founder and CEO Ronghui Gu warns against deploying AI agents without scanning them for viruses and isolating them before granting them further access to sensitive data and accounts.(Ronghui Gu)

"The scam apps use natural language to influence behavior, making them totally resistant to traditional antivirus scans," Gu explained.

Key facts

Summary

Security firm CertiK warns that the rapid deployment of autonomous AI agents, often unisolated and unvetted, is creating a massive and dangerous “security debt” across networks and applications. By granting AI agents access to local files, credentials and financial tools, users are effectively creating powerful insider threats that can be hijacked through prompt-injection attacks and malicious plug-ins. CertiK’s research has uncovered widespread vulnerabilities and a surge in short-lived, automated on-chain scams targeting other AI systems, prompting calls for a shift to strict Zero Trust architectures for AI agent infrastructure. The global rush to deploy autonomous AI agents across the internet, enterprise networks and consumer applications is creating a catastrophic security debt, according to the chief of blockchain security auditor Certik. While corporations ambitiously market these tools as productivity miracles, the crude reality is that it can be a very, risky thing to do.

#AI Agent #CertiK