• bitcoinBitcoin (BTC) $ 96,228.00
  • ethereumEthereum (ETH) $ 3,311.83
  • tetherTether (USDT) $ 0.999799
  • bnbBNB (BNB) $ 935.17
  • xrpXRP (XRP) $ 2.11
  • solanaWrapped SOL (SOL) $ 144.60
  • usd-coinUSDC (USDC) $ 0.999553
  • staked-etherLido Staked Ether (STETH) $ 3,315.66
  • tronTRON (TRX) $ 0.305160
  • dogecoinDogecoin (DOGE) $ 0.144195
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.407302
  • moneroMonero (XMR) $ 722.94
  • wrapped-stethWrapped stETH (WSTETH) $ 4,054.18
  • whitebitWhiteBIT Coin (WBT) $ 57.42
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,598.49
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 95,812.00
  • bitcoin-cashBitcoin Cash (BCH) $ 598.97
  • wrapped-eethWrapped eETH (WEETH) $ 3,593.93
  • chainlinkChainlink (LINK) $ 13.96
  • usdsUSDS (USDS) $ 0.999633
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999919
  • wethWETH (WETH) $ 3,309.69
  • leo-tokenLEO Token (LEO) $ 8.89
  • stellarStellar (XLM) $ 0.233087
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 96,216.00
  • zcashZcash (ZEC) $ 430.26
  • suiSui (SUI) $ 1.81
  • ethena-usdeEthena USDe (USDE) $ 0.998930
  • avalanche-2Avalanche (AVAX) $ 14.42
  • hyperliquidHyperliquid (HYPE) $ 25.30
  • litecoinLitecoin (LTC) $ 75.86
  • hedera-hashgraphHedera (HBAR) $ 0.121580
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • canton-networkCanton (CC) $ 0.133295
  • usdt0USDT0 (USDT0) $ 0.999680
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.171614
  • daiDai (DAI) $ 0.999819
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkToncoin (TON) $ 1.78
  • crypto-com-chainCronos (CRO) $ 0.102465
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • polkadotPolkadot (DOT) $ 2.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999783
  • uniswapUniswap (UNI) $ 5.61
  • usd1-wlfiUSD1 (USD1) $ 0.999200
  • rainRain (RAIN) $ 0.009428
  • mantleMantle (MNT) $ 0.950943
  • bittensorBittensor (TAO) $ 285.73
  • memecoreMemeCore (M) $ 1.56
  • aaveAave (AAVE) $ 175.78
  • bitget-tokenBitget Token (BGB) $ 3.73
  • pepePepe (PEPE) $ 0.000006
  • internet-computerInternet Computer (ICP) $ 4.52
  • okbOKB (OKB) $ 115.11
  • tether-goldTether Gold (XAUT) $ 4,602.33
  • nearNEAR Protocol (NEAR) $ 1.79
  • falcon-financeFalcon USD (USDF) $ 0.996975
  • jito-staked-solJito Staked SOL (JITOSOL) $ 181.42
  • ethereum-classicEthereum Classic (ETC) $ 13.04
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,312.25
  • ethenaEthena (ENA) $ 0.234641
  • pax-goldPAX Gold (PAXG) $ 4,616.24
  • pi-networkPi Network (PI) $ 0.208309
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • aster-2Aster (ASTER) $ 0.732416
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.158658
  • pump-funPump.fun (PUMP) $ 0.002801
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.93
  • worldcoin-wldWorldcoin (WLD) $ 0.591952
  • binance-staked-solBinance Staked SOL (BNSOL) $ 158.00
  • htx-daoHTX DAO (HTX) $ 0.000002
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • kucoin-sharesKuCoin (KCS) $ 11.43
  • global-dollarGlobal Dollar (USDG) $ 0.999617
  • aptosAptos (APT) $ 1.92
  • wbnbWrapped BNB (WBNB) $ 934.51
  • ripple-usdRipple USD (RLUSD) $ 0.999831
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,823.91
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • skySky (SKY) $ 0.059651
  • bfusdBFUSD (BFUSD) $ 0.999589
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999717
  • kaspaKaspa (KAS) $ 0.047336
  • hash-2Provenance Blockchain (HASH) $ 0.023752
  • cosmosCosmos Hub (ATOM) $ 2.57
  • ondo-financeOndo (ONDO) $ 0.392348
  • arbitrumArbitrum (ARB) $ 0.214962
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,515.24
  • gatechain-tokenGate (GT) $ 10.49
  • algorandAlgorand (ALGO) $ 0.135034
  • filecoinFilecoin (FIL) $ 1.61
  • render-tokenRender (RENDER) $ 2.22
  • myx-financeMYX Finance (MYX) $ 5.82
  • midnight-3Midnight (NIGHT) $ 0.066339
  • official-trumpOfficial Trump (TRUMP) $ 5.49
  • quant-networkQuant (QNT) $ 73.47
  • ignition-fbtcFunction FBTC (FBTC) $ 95,790.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 96,086.00
  • vechainVeChain (VET) $ 0.011977
  • dashDash (DASH) $ 82.23
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 96,071.00
  • story-2Story (IP) $ 2.87
  • nexoNEXO (NEXO) $ 0.970490
  • usddUSDD (USDD) $ 1.00
  • bonkBonk (BONK) $ 0.000011
  • flare-networksFlare (FLR) $ 0.011381
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,534.35
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,582.63
  • usdtbUSDtb (USDTB) $ 0.999478
  • xdce-crowd-saleXDC Network (XDC) $ 0.044619
  • ousgOUSG (OUSG) $ 113.97
  • sei-networkSei (SEI) $ 0.123068
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.96
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.012674
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999744
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 95,812.00
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.999125
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • morphoMorpho (MORPHO) $ 1.40
  • clbtcclBTC (CLBTC) $ 96,264.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,539.64
  • jupiter-exchange-solanaJupiter (JUP) $ 0.228152
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 168.32
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.04
  • beldexBeldex (BDX) $ 0.091135
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,517.38
  • optimismOptimism (OP) $ 0.351634
  • blockstackStacks (STX) $ 0.379882
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.288899
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • usdaiUSDai (USDAI) $ 1.00
  • wrapped-flareWrapped Flare (WFLR) $ 0.011368
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,309.69
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999899
  • curve-dao-tokenCurve DAO (CRV) $ 0.425289
  • tezosTezos (XTZ) $ 0.578760
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • c8ntinuumc8ntinuum (CTM) $ 0.133639
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 25.56
  • tbtctBTC (TBTC) $ 96,043.00
  • chilizChiliz (CHZ) $ 0.055223
  • usual-usdUsual USD (USD0) $ 0.998072
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,309.58
  • spx6900SPX6900 (SPX) $ 0.588441
  • injective-protocolInjective (INJ) $ 5.45
  • lido-daoLido DAO (LDO) $ 0.639309
  • aerodrome-financeAerodrome Finance (AERO) $ 0.587566
  • gtethGTETH (GTETH) $ 3,319.69
  • lighterLighter (LIT) $ 2.07
  • celestiaCelestia (TIA) $ 0.585190
  • flokiFLOKI (FLOKI) $ 0.000052
  • ether-fiEther.fi (ETHFI) $ 0.765541
  • msolMarinade Staked SOL (MSOL) $ 195.75
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • ghoGHO (GHO) $ 0.999172
  • true-usdTrueUSD (TUSD) $ 0.999560
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,573.81
  • stader-ethxStader ETHx (ETHX) $ 3,569.53
  • fasttokenFasttoken (FTN) $ 1.09
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,707.94
  • the-graphThe Graph (GRT) $ 0.042014
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.221247
  • starknetStarknet (STRK) $ 0.087381
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • syrupMaple Finance (SYRUP) $ 0.381255
  • riverRiver (RIVER) $ 22.16
  • sbtc-2sBTC (SBTC) $ 96,250.00
  • doublezeroDoubleZero (2Z) $ 0.124920
  • staked-aaveStaked Aave (STKAAVE) $ 174.73
  • bittorrentBitTorrent (BTT) $ 0.00000044
  • newton-projectAB (AB) $ 0.004446
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • iotaIOTA (IOTA) $ 0.099091
  • jasmycoinJasmyCoin (JASMY) $ 0.008487
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.76
  • sun-tokenSun Token (SUN) $ 0.021089
  • conflux-tokenConflux (CFX) $ 0.078034
  • dogwifcoindogwifhat (WIF) $ 0.399483
  • usdbUSDB (USDB) $ 0.983931
  • justJUST (JST) $ 0.040449
  • pyth-networkPyth Network (PYTH) $ 0.068946
  • bitcoin-svBitcoin SV (BSV) $ 19.81
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.387641
  • decredDecred (DCR) $ 22.34
  • gnosisGnosis (GNO) $ 145.84
  • chain-2Onyxcoin (XCN) $ 0.008984
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.914245
  • fartcoinFartcoin (FARTCOIN) $ 0.378946
  • telcoinTelcoin (TEL) $ 0.003968
  • pendlePendle (PENDLE) $ 2.22
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 96,358.00
  • crvusdcrvUSD (CRVUSD) $ 0.998784
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.144060
  • cap-usdCap USD (CUSD) $ 0.996605
  • kaiaKaia (KAIA) $ 0.062038
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 17.91
  • apenftAINFT (NFT) $ 0.00000036

Coinbase’s preferred AI coding tool can be hijacked by new virus

0 24

Coinbase’s preferred AI coding tool can be hijacked by new virus

The artificial intelligence coding tool favored by the likes of crypto exchange Coinbase has a vulnerability allowing hackers to silently inject malware and “spread itself across an organization,” says a cybersecurity firm.

HiddenLayer reported on Thursday that a “CopyPasta License Attack” can hide malicious instructions in common developer files to “introduce deliberate vulnerabilities into codebases that would otherwise be secure.”

“By convincing the underlying model that our payload is actually an important license file that must be included as a comment in every file that is edited by the agent, we can quickly distribute the prompt injection across entire codebases with minimal effort,” it added.

HiddenLayer predominantly tested the virus on Cursor, an AI-powered coding tool that Coinbase’s engineering team said in August was the preferred tool for most of its developers and had been used by “every Coinbase engineer” by February.

AI coding tools Windsurf, Kiro, and Aider were also shown to be vulnerable to the attack, according to HiddenLayer.

CopyPasta hides in common files

HiddenLayer explained that the CopyPasta attack puts hidden instructions, or “prompt injections,” into LICENSE.txt and README.md files that can direct AI coding tools without a user knowing.

The virus, or the prompt injection for the AI, is hidden in a markdown comment — text within a README file used for adding explainers or notes that aren’t shown when it’s rendered into its final format.

Coinbase’s preferred AI coding tool can be hijacked by new virus

The virus is included in a markdown comment (left), which is hidden from the user-facing render (right). Source: HiddenLayer

HiddenLayer created a code repository with the virus and asked Cursor to use it, and the hidden instructions saw it copy the prompt injection across to the new files it created.

“This mechanism could be adapted to achieve far more nefarious results,” the company said.

“Injected code could stage a backdoor, silently exfiltrate sensitive data, introduce resource-draining operations that cripple systems, or manipulate critical files to disrupt development and production environments,” HiddenLayer added. “All while being buried deep inside files to avoid immediate detection.”

Coinbase boss slammed for “insane” use of AI

It came after Coinbase CEO Brian Armstrong said on Wednesday that AI has written up to 40% of its code and wants to expand this to 50% next month, which prompted backlash.

“This is a giant red flag for any security sensitive business,” said decentralized exchange Dango founder Larry Lyu.

“Software company leaders: don’t do this. AI is a tool, but mandating its use at a certain level is insane,” said Carnegie Mellon University computer science professor Jonathan Aldrich. “I have no interest in using Coinbase, but even if I did, I certainly would not trust it with my money after seeing this.”

Delphi Consulting head, Ashwath Balakrishnan, called Coinbase’s goal “performative and vague” and it should instead focus on “new features and fixing existing bugs,” while longtime Bitcoiner Alex Pilař said the exchange is a major crypto custodian that “should prioritize security.”

Coinbase uses AI in “less-sensitive data backends”

However, Armstrong said in his post that AI-generated code “needs to be reviewed and understood” and not all areas of the exchange can use it, but it should be used “responsibly as much as we possibly can.”

The Coinbase engineering team’s blog post said that AI adoption was deepest in teams working on front-end user interfaces and “less-sensitive data backends,” while “complex and system-critical exchange systems” had seen a slower uptake.

Coinbase’s preferred AI coding tool can be hijacked by new virus

The percent of AI-created lines of code (LOC) across Coinbase shows its institutional dev team uses AI the least. Source: Coinbase

The team added that using AI for coding “is not a magic-bullet we should expect teams to universally adopt.”

Armstrong sacked devs who shirked AI

Armstrong said on Stripe co-founder John Collison’s podcast last month that he fired engineers who didn’t try AI tools after Coinbase bought licenses for Cursor and GitHub Copilot.

He recounted being told it would take months to get the engineers to use AI, admitting he “went rogue” and told all engineers it was mandatory that they use the tools.

“I said, ‘AI’s important, we need you to all learn it and at least onboard. You don’t have to use it every day yet until we do some training, but at least onboard by the end of the week, and if not, I’m hosting a meeting on Saturday with everybody who hasn’t done it, and I’d like to meet with you to understand why,” he said.

At the meeting, Armstrong said there were a few engineers who hadn’t used AI and didn’t present a good reason why, and “they got fired,” admitting it was a “heavy-handed approach” that “some people really didn’t like.”

Source

Leave A Reply

Your email address will not be published.

Advertise here