CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: New ChatGPT Agent Can Book, Browse, and Fill Forms—Just Don’t Trust It Yet
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > New ChatGPT Agent Can Book, Browse, and Fill Forms—Just Don’t Trust It Yet
News

New ChatGPT Agent Can Book, Browse, and Fill Forms—Just Don’t Trust It Yet

CoinRSS
Last updated: July 25, 2025 4:14 pm
CoinRSS Published July 25, 2025
Share

Contents
In briefGenerally Intelligent Newsletter

In brief

  • OpenAI rolled out ChatGPT agent to subscribers, enabling web access and task automation.
  • The company warned users about prompt injection attacks that could exploit the agent’s permissions.
  • Experts recommend caution, limited access, and layered security to reduce risks.

OpenAI rolled out its ChatGPT agent to Plus, Pro, and Team subscribers on Thursday, offering users a powerful new way to automate online tasks. But the launch came with a warning: the agent could expose users to prompt injection attacks.

“When you sign ChatGPT agent into websites or enable connectors, it will be able to access sensitive data from those sources, such as emails, files, or account information,” OpenAI wrote in a blog post.

The feature will also be able to take actions, such as sharing files or modifying account settings.

“This can put your data and privacy at risk due to the existence of ‘prompt injection’ attacks online, OpenAI conceded.

A prompt injection is a type of attack where malicious actors embed hidden instructions in content that an AI agent might read, such as blog posts, website text, or email messages.

If successful, the injected prompt can trick the agent into taking unintended actions, such as accessing personal data or sending sensitive information to an attacker’s server.

OpenAI announced the AI agent on July 17, initially planning a full rollout the following Monday.

That timeline slipped to July 24, when the company launched the feature alongside an app update.

ChatGPT agent can log into websites, read emails, make reservations, and interact with services like Gmail, Google Drive, and GitHub.

While designed to boost productivity, the agent also creates new security risks tied to how AI systems interpret and execute instructions.

According to Steven Walbroehl, CTO and co-founder of blockchain and AI cybersecurity firm Halborn, prompt injection is essentially a form of command injection, but with a twist.

“It’s a command injection, but the command injection, instead of being like code, it’s more social engineering,” Walbroehl told Decrypt. “You’re trying to trick or manipulate the agent to do things that are outside the bounds of its parameters.”

Unlike traditional code injections, which rely on precise syntax, prompt injection exploits the fuzziness of natural language.

“With code injection, you’re working with structured, predictable input. Prompt injection flips that: You’re using natural language to slip malicious instructions past the AI’s guardrails,” Walbroehl said.

He warned that malicious agents could impersonate trusted ones and advised users to verify their sources and use safeguards such as endpoint encryption, manual overrides, and password managers.

However, even multi-factor authentication may not be enough if the agent can access email or SMS.

“If it can see the data, or log keystrokes, it doesn’t matter how secure your password is,” Walbroehl said. “Even multi-factor authentication can fail if the agent fetches backup codes or SMS texts. The only real protection might be biometrics—something you are, not something you have.”

OpenAI recommends using the “Takeover” feature when entering sensitive credentials. That pauses the agent and hands control back to the user.

To defend against prompt injection and other AI-related threats in the future, Walbroehl recommended a layered approach, using specialized agents to strengthen security.

“You could have one agent always acting as a watchdog,” he said. “It could monitor for heuristics or behavior patterns that indicate a potential attack before it happens.”

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

Source link

You Might Also Like

Strategy Reveals $4.2 Billion Stock Sale After Missing First Weekly Bitcoin Buy in 3 Months

Ethereum price drops after hack #2 – But why investors aren’t panicking

SUI crosses $3.5 – Assessing if bulls can regain control

Judge Tosses NFT Lawsuit Against Dolce & Gabbana USA

Ripple Stuck With $125 Million Penalty as Judge Denies XRP Settlement With SEC

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Ethereum: $160M in shorts get wiped out – Will ETH’s rally last?
Next Article Bitcoin – Why BTC’s ‘air gap’ at $117K could spark major market shifts
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
$13 million in crypto liquidations after altcoin leverage hits all-time high – Details
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?