Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Galaxy cuts CLARITY Act odds as Senate clock runs out

    June 8, 2026

    Clawdbot creator Peter Steinberger: ‘Crypto folks, stop harassing me’

    June 8, 2026

    Yuga Labs rescues 68 NFTs after Flooring Protocol exploit

    June 8, 2026
    Facebook X (Twitter) Instagram
    Cryptify Now
    • Home
    • Features
      • Typography
      • Contact
      • View All On Demos
    • Typography
    • Buy Now
    X (Twitter) Instagram YouTube LinkedIn
    Cryptify Now
    You are at:Home » Google flags first AI-assisted zero-day attack targeting 2FA
    Crypto

    Google flags first AI-assisted zero-day attack targeting 2FA

    James WilsonBy James WilsonMay 12, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Google’s Threat Intelligence Group said it found a zero-day exploit that likely used artificial intelligence during discovery and weaponization. 

    Summary

    • Google’s report links AI to a zero-day 2FA bypass targeting a popular admin tool today.
    • The exploit needed valid credentials first, but removed the second authentication barrier for attackers later.
    • Crypto users face added risk as AI agents, wallets, and connectors attract phishing attempts online.

    The exploit targeted a popular open-source, web-based system administration tool and allowed attackers to bypass two-factor authentication after gaining valid login details.

    The group said it worked with the affected vendor to disclose the flaw and stop the planned mass exploitation campaign. Google did not name the tool, the vendor, or the threat actor behind the operation.

    Exploit needed valid credentials first

    The flaw did not give attackers full access on its own. Google said the bypass required valid user credentials before the attacker could skip the second login step. That detail matters because two-factor authentication often protects crypto accounts, exchange logins, developer dashboards, and wallet-linked services.

    Google said the weakness came from a logic error, not a common coding bug such as memory corruption or poor input handling. The company described it as a high-level semantic flaw, where a hardcoded trust assumption conflicted with the tool’s 2FA checks.

    Moreover, Google said it had “high confidence” that the actor likely used an AI model to support discovery and weaponization of the vulnerability. The company said the exploit script included educational comments, a hallucinated CVSS score, and a clean Python format often linked to large language model output.

    The company also said it does not believe Gemini was used in the operation. Its report noted that China and North Korea-linked actors have shown interest in AI-assisted vulnerability research, including prompt-based security testing and large-scale analysis of known flaws.

    Crypto security risks widen

    The warning adds to rising concern over AI tools in crypto security. Separate reports have tracked OpenClaw-related phishing, where attackers used cloned websites and malicious wallet prompts to target developers and drain crypto wallets.

    Other security coverage has also warned that AI agents can create new weak points when they process outside content, connect to third-party tools, or act without enough human approval. Those risks are more serious when agents can access wallets, private files, browser data, or account credentials.

    Google said threat actors are also testing AI for malware support, defense evasion, information operations, and access to AI systems. It named malware families such as PROMPTFLUX, HONESTCUE, and CANFAIL as examples of tools using LLMs for obfuscation or decoy code.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBitcoin dropped to $0.019 on Revolut today
    Next Article Bitcoin treasury firm Strive buys Strategy instead of bitcoin
    James Wilson

    Related Posts

    Galaxy cuts CLARITY Act odds as Senate clock runs out

    June 8, 2026

    Yuga Labs rescues 68 NFTs after Flooring Protocol exploit

    June 8, 2026

    Michael Saylor fires back after Cramer blames him for Bitcoin crash

    June 8, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Michael Saylor diluted MSTR by $735.2 million after saying he wouldn’t

    April 8, 2026

    SEC says some of its past crypto enforcement cases misinterpreted securities laws

    April 8, 2026

    What Are Digital Assets? A Complete Guide for Enterprise

    April 8, 2026

    Security Alert – Geth suffers from a very low probable DoS attack vector – Update immediately

    April 8, 2026
    Don't Miss

    Galaxy cuts CLARITY Act odds as Senate clock runs out

    By James WilsonJune 8, 2026

    Galaxy Digital has lowered its estimate for the CLARITY Act becoming law in 2026, warning…

    Clawdbot creator Peter Steinberger: ‘Crypto folks, stop harassing me’

    June 8, 2026

    Yuga Labs rescues 68 NFTs after Flooring Protocol exploit

    June 8, 2026

    Trove Markets perpetrator is Chinese crypto scammer, report

    June 8, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    CryptifyNow: Your daily source for the latest insights, news, and analysis in the ever-evolving world of cryptocurrency.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Galaxy cuts CLARITY Act odds as Senate clock runs out

    June 8, 2026

    Clawdbot creator Peter Steinberger: ‘Crypto folks, stop harassing me’

    June 8, 2026

    Yuga Labs rescues 68 NFTs after Flooring Protocol exploit

    June 8, 2026
    Lithosphere News Releases

    Lithosphere Introduces Decentralized Naming and Routing for Web4 Infrastructure

    April 21, 2026

    Lithosphere Reduces Blockchain Fragmentation Through MultX Interoperability Engine

    April 21, 2026

    Lithosphere’s MultX Enables Unified Cross-Chain Liquidity Access for Intelligent Systems

    April 22, 2026
    Copyright © 2026

    Type above and press Enter to search. Press Esc to cancel.