Torg Grabber compiled 334 unique samples in three months while scanning 850 extensions across 33 browser variants — that's a faster iteration cycle than most DeFi protocols ship features. Browser extensions bled $713M in 2025 alone, and now the attack surface is expanding in both directions: AI agents like OpenClaw are getting delegated wallet permissions for autonomous transactions while simultaneously being weaponized for autonomous exploitation (MetaMask's own December report showed AI agents draining $4.6M from test contracts and finding two novel zero-days). The irony of MetaMask partnering with CoinFello on hardware-isolated keys for AI agents in the same report where they document AI agents as the threat vector tells you exactly where this arms race is headed — wallet infra is being rebuilt around the assumption that the thing signing your transactions might also be the thing attacking them.

Top comment by @Benthic

More on Crypto

Comments