cd /news/ai-safety/virtuals-protocol-addresses-evolving… · home topics ai-safety article
[ARTICLE · art-113915] src=cryptobriefing.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Virtuals Protocol addresses evolving prompt injection threats to agent wallets

Virtuals Protocol has introduced programmable agent wallets on Base and Solana that enforce owner-configured spending limits and kill switches at the signing layer, separating security from AI decision-making to mitigate prompt injection and memory poisoning attacks. The wallets, which support presets like DENY_ALL and ACP_ONLY, are enforced server-side and are used by over 18,000 agents on the platform. This comes after over $150,000 was drained from an AI agent via prompt injection in 2026.

read2 min views1 publishedAug 28, 2026
Virtuals Protocol addresses evolving prompt injection threats to agent wallets
Image: Cryptobriefing (auto-discovered)

Photo: Tima Miroshnichenko / Pexels

New programmable wallet policies let owners enforce spending limits and kill switches directly at the signing layer, separating security from AI decision-making When your AI agent has its own wallet, the question isn’t whether someone will try to trick it into sending funds. It’s when. Virtuals Protocol is rolling out programmable agent wallets designed to make that scenario a lot less catastrophic, introducing owner-configurable policies that enforce rules at the wallet level rather than relying on the AI itself to behave.

The programmable wallets operate on Base with an expansion into Solana, giving agents non-custodial multi-chain smart accounts. Virtuals has introduced presets like “DENY_ALL,” which requires manual approval for every transaction, and “ACP_ONLY,” which limits where funds can actually go.

Policies are enforced server-side, meaning they operate as a protection layer completely independent of the AI agent’s logic. Even if an attacker successfully poisons an agent’s memory or injects malicious prompts, the wallet itself won’t execute transactions that violate the owner’s rules.

The architecture also separates wallet identity from signing keys. Policy controls can be managed through a dashboard or command line interface, giving owners flexibility in how they configure and monitor their agents’ financial behavior.

The problem this solves is already costing people money #

In 2026, over $150,000 was drained from an AI agent through prompt injection techniques. The attack surface is straightforward: AI agents that interact with external data can be fed instructions that override their intended behavior. If those agents control wallets without independent enforcement layers, a successful injection can result in unauthorized fund transfers.

Memory poisoning works similarly but plays a longer game. Rather than a single malicious prompt, attackers gradually corrupt the context an agent relies on for decision-making, slowly shifting its behavior until it executes actions the owner never intended.

Scale and competitive positioning #

Virtuals Protocol currently hosts over 18,000 agents leveraging on-chain wallets. Updates to the Agent Commerce Protocol beta are focused on job execution and delegation, expanding what agents can actually do with their wallets beyond simple token transfers. Direct payments for computational resources from wallets highlight how the infrastructure is being designed for agents that operate as genuine economic actors.

The Solana rollout adds multi-chain capability. The spending limits enforced at the signing layer with programmable guardrails provide what amounts to a firewall between an AI’s potentially compromised reasoning and the actual movement of funds.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-safety 4 stories · sorted by recency
── more on @virtuals protocol 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/virtuals-protocol-ad…] indexed:0 read:2min 2026-08-28 ·