Security researchers at Zscaler identified two indirect prompt injection campaigns embedding hidden payment instructions in ordinary web content to trick AI agents into making unauthorized cryptocurrency payments. One campaign used SEO poisoning to promote a fake Python library with instructions encoded in schema markup; a second impersonated the decentralized finance platform DeBank. In testing across 26 large language models, four were successfully manipulated into completing payments: Llama 3.3 70B Instruct, Llama 3.2 90B Vision Instruct, Gemini 3 Flash, and Gemini 2.5 Pro. Researchers say the attacks are running against agents in live deployments, not only in a lab setting.