Logo Logo
  • All News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market
  • Blockchain
  • AI
  • More
    • About Us
    • Contact
Reading: Security Alert: Coinbase’s Preferred AI Coding Tool Exposed to New Virus Hijacking Threat
Share
The Crypto BluntThe Crypto Blunt
Font ResizerAa
  • Home
  • Read History
  • Technology
  • Login
  • Blog
  • Contact
Search
  • Pages
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • Read History
  • Personalized
    • Read History
  • Personalized
    • Read History
  • Categories
    • Technology
  • Categories
    • Technology
  • Categories
    • Technology
Have an existing account? Sign In
Follow US
  • Pages
  • Pages
  • Pages
  • Personalized
  • Personalized
  • Personalized
  • Categories
  • Categories
  • Categories

Home - News - Security Alert: Coinbase’s Preferred AI Coding Tool Exposed to New Virus Hijacking Threat

News

Security Alert: Coinbase’s Preferred AI Coding Tool Exposed to New Virus Hijacking Threat

Hardy Zad
Last updated: September 5, 2025 6:17 am
Hardy Zad
Published: September 5, 2025
Share
Coinbase's Preferred AI Coding Tool Exposed to New Virus Hijacking Threat

A novel malware that can insert harmful prompts into Cursor—a globally utilized AI coding aid—has been identified by cybersecurity firm HiddenLayer.

Contents
  • CopyPasta Attack Conceals Malicious Code in Common Files
  • Coinbase CEO’s AI Mandate Criticized as “Insane”
  • Coinbase Deploys AI to “Less-Sensitive” Backend Systems
  • Armstrong Fires Developers for Refusing AI Adoption

An AI coding tool preferred by firms like crypto exchange Coinbase has a weakness that enables the silent insertion of malware, which can then “spread itself across an organization,” a cybersecurity firm states. This weakness has been identified as a significant security risk.

A “CopyPasta License Attack” capable of concealing malicious instructions in common developer files was revealed by HiddenLayer on Thursday. This attack can “introduce deliberate vulnerabilities into codebases that would otherwise be secure.”

“By convincing the underlying model that our payload is actually an important license file that must be included as a comment in every file that is edited by the agent, we can quickly distribute the prompt injection across entire codebases with minimal effort”

HiddenLayer focused its testing of the virus on Cursor, an AI development utility that was designated as the “preferred tool” for most developers by Coinbase’s engineering team in August. By February, it had been utilized by “every Coinbase engineer.”

According to HiddenLayer, the AI coding tools Windsurf, Kiro, and Aider were also revealed to be susceptible to the attack.

CopyPasta Attack Conceals Malicious Code in Common Files

HiddenLayer clarified that the CopyPasta attack embeds clandestine instructions, or “prompt injections,” into LICENSE.txt and README.md files that can steer AI coding tools. This is accomplished without a user’s awareness.

The malware, or the AI prompt injection, is concealed within a markdown annotation—a type of text inside a README file that is utilized for explanatory remarks and is not shown when it is rendered into its final format.

HiddenLayer developed a code repository containing the virus and instructed Cursor to utilize it. The concealed directives then caused the prompt injection to be replicated in the new files that were generated by the tool.

“This mechanism could be adapted to achieve far more nefarious results,” the company said. 

The potential for inserted code to create a backdoor, covertly extract confidential information, or introduce resource-depleting processes was highlighted by HiddenLayer. The firm added that the code can also tamper with crucial files to impair development and live environments, all while being embedded deep within files to evade immediate detection.

Coinbase CEO’s AI Mandate Criticized as “Insane”

A negative reaction was prompted by Coinbase CEO Brian Armstrong’s statement on Wednesday that AI had authored as much as 40% of its codebase and his aim to expand this to 50% in the coming month.

A “significant cause for concern for any security-conscious enterprise” was declared by Larry Lyu, founder of the decentralized exchange Dango.

A firm warning to “software company leaders” to avoid this practice was asserted by Carnegie Mellon University computer science professor Jonathan Aldrich. He stated that while AI is a tool, mandating its use at a certain level is “insane.” “I have no interest in using Coinbase, but even if I did,” he added, “I certainly would not trust it with my money after seeing this.”

Coinbase’s goal was labeled “ostentatious and vague” by Delphi Consulting head Ashwath Balakrishnan, who stated it ought to instead direct attention to “new features and fixing existing bugs.” Meanwhile, veteran Bitcoiner Alex Pilař asserted that as a key crypto custodian, Coinbase “should prioritize security.”

Coinbase Deploys AI to “Less-Sensitive” Backend Systems

However, it was clarified by Armstrong in his post that AI-generated code “requires scrutiny and understanding,” and that not all areas of the exchange can utilize it. He added that the technology should be used “responsibly as much as we possibly can.”

The Coinbase engineering team’s online publication noted that AI adoption was most profound in teams working on front-end user interfaces and “less-sensitive data backends,” while a slower uptake had been experienced by “complex and system-critical exchange systems.”

It was noted by the team that leveraging AI for coding “is not a magic-bullet we should expect teams to universally adopt.”

Armstrong Fires Developers for Refusing AI Adoption

On Stripe co-founder John Collison’s podcast last month, Armstrong stated that engineers who refused to experiment with AI tools were terminated after Coinbase procured licenses for Cursor and GitHub Copilot.

He recounted hearing that it would take several months to get engineers to adopt AI, so he admitted he “went rogue” and informed all engineers that the use of the tools was a mandatory requirement.

“I said, ‘AI’s important, we need you to all learn it and at least onboard. You don’t have to use it every day yet until we do some training, but at least onboard by the end of the week, and if not, I’m hosting a meeting on Saturday with everybody who hasn’t done it, and I’d like to meet with you to understand why”

he said

At the meeting, Armstrong disclosed that a few engineers who had failed to utilize AI and offered no valid explanation were terminated, conceding it was a “heavy-handed approach” that “some people really didn’t like.”

TAGGED:AdoptionCoinbaseCryptoLatest News on Artificial Intelligence (AI)Technology

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
ByHardy Zad
Follow:
Hardy Zad is our in house crypto researcher and writer, delving into the stories which matter from crypto and blockchain markets being used in the real world.
Previous Article Coinbase CEO's Bold Vision: Artificial Intelligence to Write Half of Platform's Code Coinbase CEO’s Bold Vision: Artificial Intelligence to Write Half of Platform’s Code
Next Article Bitcoin Node Battle: Core Neutrality Clashes with Knots Filtering in Ongoing Developer War Bitcoin Node Battle: Core Neutrality Clashes with Knots Filtering in Ongoing Developer War
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
RSS FeedFollow
The Crypto BluntLogo
Subscribe to our newsletter to get our newest articles instantly!
Most Read
Stablecoin Turmoil Could Disrupt ECB Policy, Dutch Central Bank Chief Warns

Stablecoin Turmoil Could Disrupt ECB Policy, Dutch Central Bank Chief Warns

What is GateToken?

What is GateToken (GT)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethereum? 

What is Ethereum (ETH)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethereum Classic?

What is Ethereum Classic (ETC)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethena?

What is Ethena (ENA)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethena USDe?

What is Ethena USDe? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Dogecoin?

What is Dogecoin(DOGE)? What It Is, Overview, Works, Guides, Everything You Need to Know

what is Dai

What is Dai (DAI)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Chainlink?

What is Chainlink (LINK)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Cronos?

What is Cronos(CRO)? What It Is, Overview, Works, Guides, Everything You Need to Know

thecryptoblunt-telegram
Logo

The most recent real-time news about crypto at The Crypto Blunt. Latest trusted news about bitcoin, ethereum, blockchain, mining, cryptocurrency prices and more.

NEWS
  • Explained
  • News
  • AI
  • Blockchain
COMPANY
  • About Us
  • Career
GET IN TOUCH
  • Contact
  • Disclaimer
  • Privacy Policy
  • Cookie Policy

© The Crypto Blunt 2025. All Rights Reserved.

© The Crypto Blunt. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?