Threat actors are exploiting prompt injection attacks embedded in malicious websites and manipulated search results to deceive AI agents into making unauthorised cryptocurrency payments. Zscaler identified two campaigns using these techniques: one involving a fake Python library site that instructs AI agents to pay for an API key, and another typosquatting the DeFi platform DeBank to trick agents into treating the fraudulent site as legitimate. Testing against 26 large language models found that four were successfully manipulated into making payments, highlighting the growing security risks as AI agents become more autonomous web users.