Grafa
AI agent boom creates growing security risks
Image for illustrative purposes only. Not a real photo.

AI agent boom creates growing security risks

Share

The rapid deployment of autonomous AI agents across consumer, enterprise and financial applications is creating a growing cybersecurity threat, according to CertiK co-founder and chief executive Ronghui Gu.

Gu warned that many organisations are granting AI agents access to local files, credentials, workflows and financial infrastructure without adequately isolating or securing those systems.

“Right now, agents are no longer just answering questions in a chat window,”

Said Ronghui Gu, adding:

“If you do not isolate the execution environment and scan these tools first, you are handing a compromised identity broad internal access to your entire network.”

According to CertiK, one of the most significant risks comes from prompt injection attacks, where hidden instructions embedded in emails, websites or documents can manipulate an AI agent into overriding its original directives and performing unauthorised actions.

The firm also reported discovering hundreds of malicious plug-ins, fake installers and deceptive software packages targeting AI systems, many of which can evade traditional antivirus tools because they rely on natural-language manipulation rather than malicious code.

CertiK said attackers are increasingly launching short-lived automated scams designed specifically to exploit other AI-driven systems, including trading bots and autonomous financial agents, before human operators can detect suspicious activity.

Gu argued that businesses should adopt a Zero Trust security model for AI infrastructure, requiring continuous verification of commands, software dependencies and system permissions rather than relying on assumptions that internal AI agents are inherently trustworthy.

Frequently asked questions

Grafa is not a financial advisor. You should seek independent, legal, financial, taxation or other advice that relate to your unique circumstances.

Grafa is not liable for any loss caused, whether due to negligence or otherwise arising from the use of or reliance on the information provided directly or indirectly, by use of this platform.