Blockchain security firm warns of AI code poisoning risk after OpenAI’s ChatGPT recommends scam API

Yu Xian, founder of the blockchain security firm Slowmist, has raised alarms about a rising threat known as AI code poisoning.

This attack type involves injecting harmful code into the training data of AI models, which can pose risks for users who depend on these tools for technical tasks.

The incident

The issue gained attention after a troubling incident involving OpenAI’s ChatGPT. On Nov. 21, a crypto trader named “r_cky0” reported losing $2,500 in digital assets after seeking ChatGPT’s help to create a bot for Solana-based memecoin generator Pump.fun.

However, the chatbot recommended a fraudulent Solana API website, which led to the theft of the user’s private keys. The victim noted that within 30 minutes of using the malicious API, all assets were drained to a wallet linked to the scam.

[Editor’s Note: ChatGPT appears to have recommended the API after running a search using the new SearchGPT as a ‘sources’ section can be seen in the screenshot. Therefore, it does not seem to be a case of AI poisoning but a failure of the AI to recognize scam links in search results.]

AI scam link API (Source: X)

Further investigation revealed this address consistently receives stolen tokens, reinforcing suspicions that it belongs to a fraudster.

The Slowmist founder noted that the fraudulent API’s domain name was registered two months ago, suggesting the attack was premeditated. Xian furthered that the website lacked detailed content, consisting only of documents and code repositories.

While the poisoning appears deliberate, no evidence suggests OpenAI intentionally integrated the malicious data into ChatGPT’s training, with the result likely coming from SearchGPT.

Implications

Blockchain security firm Scam Sniffer noted that this incident illustrates how scammers pollute AI training data with harmful crypto code. The firm said that a GitHub user, “solanaapisdev,” has recently created multiple repositories to manipulate AI models to generate fraudulent outputs in recent months.

AI tools like ChatGPT, now used by hundreds of millions, face increasing challenges as attackers find new ways to exploit them.

Xian cautioned crypto users about the risks tied to large language models (LLMs) like GPT. He emphasized that once a theoretical risk, AI poisoning has now materialized into a real threat. So, without more robust defenses, incidents like this could undermine trust in AI-driven tools and expose users to further financial losses.

The post Blockchain security firm warns of AI code poisoning risk after OpenAI’s ChatGPT recommends scam API appeared first on CryptoSlate.

  • Related Posts

    REX introduces BMAX ETF for Bitcoin-backed corporate bond access

    REX Shares has launched the Bitcoin Corporate Treasury Convertible Bond (BMAX) ETF, designed to give investors access to convertible bonds issued by companies using debt to acquire Bitcoin. The fund,…

    Continue reading
    Bitcoin’s rise turns 2017 theft into multimillion-pound scandal for UK officer

    British authorities have charged National Crime Agency (NCA) officer Paul Chowles with multiple offenses related to the alleged theft of 50 Bitcoin in 2017. At the time of the alleged…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Orbis86 Brings AI & Web3 to GDC 2025 – Powering the Next Era of Gaming

    Orbis86 Brings AI & Web3 to GDC 2025 – Powering the Next Era of Gaming

    REX introduces BMAX ETF for Bitcoin-backed corporate bond access

    REX introduces BMAX ETF for Bitcoin-backed corporate bond access

    Bitcoin’s rise turns 2017 theft into multimillion-pound scandal for UK officer

    Bitcoin’s rise turns 2017 theft into multimillion-pound scandal for UK officer

    Bitcoin outperforms tech stocks as US market opens to sea of green

    Bitcoin outperforms tech stocks as US market opens to sea of green

    Solana governance sets new participation record outpacing past US presidential elections

    Solana governance sets new participation record outpacing past US presidential elections

    Trump-backed DeFi project WLFI closes raise surpassing goal reaching $590 million

    Trump-backed DeFi project WLFI closes raise surpassing goal reaching $590 million