

Is this the first time you’re hearing about that particular method of credential redistribution? People are putting all sorts of personal information and secrets into a chatbot conversation and any security advancements made by changing user sentiment has been one-shotted. It’s a big problem that’s just added onto the pile of other big problems and the sign by that pile that reads, “don’t worry about it” just spontaneously caught fire.
Edit: adding this from Watchtowr as a prior example of extremely credulous user behavior that will certainly not inspire confidence, for which I am sorry.

The Watchtowr thing is totally “wallet inspectee in search of a wallet inspector” level of dumb.
One of the infosec folks I follow would post CVEs and the ones that were against AI or MCP systems were always this kind of thing. It’s crazy because I don’t think many other people express distrust about AI systems that are used for gatekeeping but I cannot trust them because waves hand at the everything.