<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>x402warden</title><link>https://457e884c.x402warden-blog.pages.dev/</link><description>Recent content on x402warden</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://457e884c.x402warden-blog.pages.dev/index.xml" rel="self" type="application/rss+xml"/><item><title/><link>https://457e884c.x402warden-blog.pages.dev/research/coinbase-agentkit-prompt-injection/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://457e884c.x402warden-blog.pages.dev/research/coinbase-agentkit-prompt-injection/</guid><description>&lt;h1 id="coinbase-agentkit-prompt-injection-wallet-drain-infinite-approvals-and-agent-level-rce">Coinbase AgentKit Prompt Injection: Wallet Drain, Infinite Approvals, and Agent-Level RCE&lt;/h1>
&lt;p>&lt;strong>Reported 13 days after Coinbase launched Agentic Wallets. Validated by Coinbase. Demonstrated on-chain.&lt;/strong>
&lt;strong>Published:&lt;/strong> April 11, 2026
&lt;strong>CVE status:&lt;/strong> Pending assignment&lt;/p>
&lt;p>Coinbase AgentKit is developer infrastructure for building AI agents with direct access to wallets, token operations, DeFi actions, and related execution surfaces. This disclosure covers a prompt injection vulnerability in AgentKit that allowed attacker-controlled input to trigger sensitive tool execution without a built-in human confirmation step.&lt;/p></description></item><item><title>About</title><link>https://457e884c.x402warden-blog.pages.dev/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://457e884c.x402warden-blog.pages.dev/about/</guid><description>About x402warden</description></item><item><title>Search</title><link>https://457e884c.x402warden-blog.pages.dev/search/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://457e884c.x402warden-blog.pages.dev/search/</guid><description>Search x402warden</description></item></channel></rss>