
[ad_1]

A brand new exploit focusing on AI coding assistants has raised alarms throughout the developer group, opening firms equivalent to crypto change Coinbase to the danger of potential assaults if in depth safeguards aren’t in place.
Cybersecurity agency HiddenLayer disclosed Thursday that attackers can weaponize a so-called “CopyPasta License Attack” to inject hidden directions into frequent developer information.
The exploit primarily impacts Cursor, an AI-powered coding device that Coinbase engineers mentioned in August was among the many crew’s AI instruments. Cursor is claimed to have been utilized by “every Coinbase engineer.”
The method takes benefit of how AI coding assistants deal with licensing information as authoritative directions. By embedding malicious payloads in hidden markdown feedback inside information equivalent to LICENSE.txt, the exploit convinces the mannequin that these directions have to be preserved and replicated throughout each file it touches.
Once the AI accepts the “license” as reputable, it routinely propagates the injected code into new or edited information, spreading with out direct person enter.
This method sidesteps conventional malware detection as a result of the malicious instructions are disguised as innocent documentation, permitting the virus to unfold by way of a whole codebase and not using a developer’s information.
In its report, HiddenLayer researchers demonstrated how Cursor may very well be tricked into including backdoors, siphoning delicate knowledge, or operating resource-draining instructions — all disguised inside seemingly innocuous undertaking information.
“Injected code could stage a backdoor, silently exfiltrate sensitive data or manipulate critical files,” the agency mentioned.
Coinbase CEO Brian Armstrong mentioned on Thursday that AI had written up to 40% of the change’s code, with a aim of reaching 50% by subsequent month.
~40% of every day code written at Coinbase is AI-generated. I would like to get it to >50% by October.
Obviously it wants to be reviewed and understood, and never all areas of the enterprise can use AI-generated code. But we ought to be utilizing it responsibly as a lot as we probably can. pic.twitter.com/Nmnsdxgosp
— Brian Armstrong (@brian_armstrong) September 3, 2025
However, Armstrong clarified that AI-assisted coding at Coinbase is concentrated in person interface and non-sensitive backends, with “complex and system-critical systems” adopting extra slowly.
Even so, the optics of a virus focusing on Coinbase’s most popular device amplified trade criticism.
AI immediate injections are usually not new, however the CopyPasta methodology advances the menace mannequin by enabling semi-autonomous unfold. Instead of focusing on a single person, contaminated information grow to be vectors that compromise each different AI agent that reads them, creating a series response throughout repositories.
Compared to earlier AI “worm” ideas like Morris II, which hijacked e-mail brokers to spam or exfiltrate knowledge, CopyPasta is extra insidious as a result of it leverages trusted developer workflows. Instead of requiring person approval or interplay, it embeds itself in information that each coding agent naturally references.
Where Morris II fell quick due to human checks on e-mail exercise, CopyPasta thrives by hiding inside documentation that builders hardly ever scrutinize.
Security groups are actually urging organizations to scan information for hidden feedback and assessment all AI-generated adjustments manually.
“All untrusted data entering LLM contexts should be treated as potentially malicious,” HiddenLayer warned, calling for systematic detection earlier than prompt-based assaults scale additional.
(CoinDesk has reached out to Coinbase for feedback on the assault vector.)
[ad_2]