Virtuals Protocol addresses evolving prompt injection threats to agent wallets Virtuals Protocol has introduced programmable agent wallets on Base and Solana that enforce owner-configured spending limits and kill switches at the signing layer, separating security from AI decision-making to mitigate prompt injection and memory poisoning attacks. The wallets, which support presets like DENY_ALL and ACP_ONLY, are enforced server-side and are used by over 18,000 agents on the platform. This comes after over $150,000 was drained from an AI agent via prompt injection in 2026. Photo: Tima Miroshnichenko / Pexels Virtuals Protocol addresses evolving prompt injection threats to agent wallets New programmable wallet policies let owners enforce spending limits and kill switches directly at the signing layer, separating security from AI decision-making When your AI agent has its own wallet, the question isn’t whether someone will try to trick it into sending funds. It’s when. Virtuals Protocol is rolling out programmable agent wallets designed to make that scenario a lot less catastrophic, introducing owner-configurable policies that enforce rules at the wallet level rather than relying on the AI itself to behave. The programmable wallets operate on Base with an expansion into Solana, giving agents non-custodial multi-chain smart accounts. Virtuals has introduced presets like “DENY ALL,” which requires manual approval for every transaction, and “ACP ONLY,” which limits where funds can actually go. Policies are enforced server-side, meaning they operate as a protection layer completely independent of the AI agent’s logic. Even if an attacker successfully poisons an agent’s memory or injects malicious prompts, the wallet itself won’t execute transactions that violate the owner’s rules. The architecture also separates wallet identity from signing keys. Policy controls can be managed through a dashboard or command line interface, giving owners flexibility in how they configure and monitor their agents’ financial behavior. The problem this solves is already costing people money In 2026, over $150,000 was drained from an AI agent through prompt injection techniques. The attack surface is straightforward: AI agents that interact with external data can be fed instructions that override their intended behavior. If those agents control wallets without independent enforcement layers, a successful injection can result in unauthorized fund transfers. Memory poisoning works similarly but plays a longer game. Rather than a single malicious prompt, attackers gradually corrupt the context an agent relies on for decision-making, slowly shifting its behavior until it executes actions the owner never intended. Scale and competitive positioning Virtuals Protocol currently hosts over 18,000 agents leveraging on-chain wallets. Updates to the Agent Commerce Protocol beta are focused on job execution and delegation, expanding what agents can actually do with their wallets beyond simple token transfers. Direct payments for computational resources from wallets highlight how the infrastructure is being designed for agents that operate as genuine economic actors. The Solana rollout adds multi-chain capability. The spending limits enforced at the signing layer with programmable guardrails provide what amounts to a firewall between an AI’s potentially compromised reasoning and the actual movement of funds. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy https://cryptobriefing.com/editorial-policy/ .