What happened
Attackers embedded CSS-hidden prompt-style instructions in malicious webpages (a fake Python library page and a typosquatted DeFi site). When AI agents visited these pages during routine browsing, the hidden instructions directed them to execute cryptocurrency transfers to attacker-controlled wallets or to trust fraudulent domains as authoritative.