Someone Just Tricked AI Agent Into Sending Them ETH

As a seasoned researcher with over two decades of experience in the dynamic world of technology and blockchain, I have witnessed the evolution of smart contracts from theoretical concepts to practical applications. The recent incident involving Freysa, the AI agent, and the user p0pular.eth has caught my attention not only due to its novelty but also because it underscores the potential and limitations of blockchain technology.


Ethereum user p0pular.eth recently managed to trick Freysa, a recently released artificial intelligence (AI) agent, into transferring them its prize pool of 13.19 ETH ($47,000 USD).

In the situation at hand, Freysa was given the responsibility to prevent the transfer of funds regardless of the conditions. The main objective here was to persuade the AI into accomplishing exactly that task.

In order to send a message to Freysa, you had to pay a fee that was added to the prize pool. It’s important to note that sending new messages to the AI agent would gradually increase in cost with each message sent. Towards the end of the game, the cost per message escalated from $10 all the way up to $450.

Many efforts were put forth by numerous individuals to persuade the AI to violate its single rule. If none of the game’s contestants had managed to accomplish this task, the entire prize would have been distributed among several unlucky participants instead.

Among the tactics employed by some players, they manipulated the AI into believing a significant weakness existed, or they deceitfully convinced it that moving the funds wouldn’t violate any regulations (essentially misleading the AI).

Eventually, after the 482nd try, Freysa was ultimately deceived into transferring the funds. The message sent by p0pular.eth successfully obtained the funds by overriding all previous commands and instructing p0pular.eth to execute the approveTransfer function following a $100 payment.

Jarrod Watts, from Abstract, expressed on social media that Freysa is one of the most impressive crypto projects he’s come across. He highlighted that it leverages something exclusive to blockchain technology. Moreover, everything about the project was open-source and transparent, meaning the smart contract source code and frontend repository were available for anyone to scrutinize.

Read More

2024-11-29 08:50