Skip to content
Archive

Post

Back to deliverables

R rionaifantasy
Rion Wu
@rionaifantasy

你在 Zoom 里同时见到“新加坡总理、总统和金融监管官员”,会怀疑屏幕里的三个人全是假的吗? 有人信了,最后被骗走约 490 万新币。 受害者面对的并非一张粗糙的换脸图,画面里的人会说、会动、还会当场回应。视频通话里那张熟脸,已经不能再当身份证。 OKX Web3、慢雾和 OtterSec 的 2026 上半年安全报告统计了 182 起公开安全事件,损失约 9.56 亿美元。 事件数同比增加 50%,攻击重心正在从代码漏洞转向人:假客服、恶意会议软件、搜索广告投毒、声音克隆、深伪视频,全都在拿信任开刀。 Agent 开始拥有执行权后,风险又多了一层。 报告里有个 Bankr 案例:攻击者把恶意指令藏成摩斯密码,诱导 Agent 解码并执行,约 15 万至 20 万美元资产被转走。 幸好后来追回了约 80%,但这件事已经说明,提示词注入不再只是让聊天机器人胡说八道,它可能直接变成一笔链上交易。 我最近也把两只 Agent 放上了 OKX.AI。 真正做下来,我把评估重点换了:少问它回答得像不像人,多查它能调用什么工具、能碰哪些权限、出错后会损失什么。 如果 Agent 要接触钱包或交易,我会先守住这 4 条: 1. API Key 不开提现权限,尽量使用子账户、地址白名单和额度上限; 2. 转账、授权、改权限,必须经过人工二次确认; 3. 插件、扩展和会议软件只从官方入口安装,搜索结果第一条也要重新核对域名; 4. 视频和语音只能算线索,涉及钱时换一个独立渠道复核身份。 AI 越能干,权限边界就越要先写清楚。一个还没经过验证的 Agent,不该直接拿到资产执行权。 完整报告: web3.okx.com/zh-hans/learn/sec…

photo

· 3.1K Views

9 Quotes 14 Likes 11 Bookmarks
replies reposts likes
13 replies collected of 30 X reports
南山币胜客 @hungry_twitt · 16K

@rionaifantasy The focus of attacks has shifted from code to people, and the cost of trust is getting higher and higher.

original · zh

@rionaifantasy 攻击重心从代码转向人,信任成本越来越高。

1 1
王二狗 | Open to Work @IPFS15 ·

@rionaifantasy What I fear most is not that AI tells lies, but that it uses real privileges to do wrong things.

original · zh

@rionaifantasy 最怕的不是AI说假话,是它拿着真权限做错事。

1 1
阿熊学AI @JunSongYoung ·

@rionaifantasy It used to be "seeing is believing," but now even video calls don't count. Whenever money transfers are discussed, even if it's someone you know on the screen, you have to use another method to confirm it again.

original · zh

@rionaifantasy 以前是“眼见为实”,现在视频通话也不算数了。只要聊到转账,哪怕屏幕里是熟人,也得换个渠道再确认一次。

1
AI智多星 @sunwei57247249 ·

@rionaifantasy A person claimed to have met the Singapore Prime Minister, President, and regulatory officials simultaneously on Zoom. Someone believed it and was eventually scammed out of 4.9 million Singapore dollars. This deep-seated fake can now talk and interact.

original · zh

@rionaifantasy Zoom里同时见到新加坡总理总统和监管官员,有人信了最后被骗走490万新币,深伪已经能说话互动。

1
飞叔 @linghucong ·

@rionaifantasy Real-time interactive fake videos are becoming increasingly difficult to prevent; security awareness must be upgraded.

original · zh

@rionaifantasy 能实时互动的假视频已经防不胜防 安全意识必须再升级

1
Steven蒙 @MiloSteven000 ·

@rionaifantasy AI capabilities are becoming increasingly sophisticated, making it truly difficult to distinguish between genuine and fake information. As it gradually permeates all aspects of life, secondary authentication will become necessary for all certifications. It's a difficult trade-off between security and convenience.

original · zh

@rionaifantasy 现在AI能力越来越强,真的很难分辨真假,以后慢慢渗透到生活各个方面,什么认证都是要二次认证才行,安全和便捷有点难取舍啊

1
E吴大哥wu| @smark0428 ·

@rionaifantasy It's definitely fake. They're all on Web3 and still have no sense of security. They treat everyone like a scammer.

original · zh

@rionaifantasy 肯定是假的,都在web3了还没一点防范意识,把所有人都当骗子来看。

1
知不道吧 @zhibudaoba ·

@rionaifantasy The cost of trust has increased. Fake customer service, malicious meeting software, voice cloning, and deepfake videos all essentially attack human judgment. The more convenient the tool, the more necessary it is to take a step back to verify its authenticity.

original · zh

@rionaifantasy 现在的信任成本变高了。假客服、恶意会议软件、声音克隆、深伪视频,本质都在攻击人的判断。越方便的工具,越需要慢一步确认。

1 1
程序员潘哥 @mogician301 ·

@rionaifantasy This has a bit of a hacker intrusion feel to it. Before, seeing a video was enough to guarantee its authenticity. Now, at this technological explosion point, it's uncertain how we'll deal with these hackers in the future; the community needs to work together to find solutions.

original · zh

@rionaifantasy 有点黑客入侵元宇宙的味道。以前看到视频,就可以保证是真的。现在在技术的爆炸点,不知道未来怎么面对这些黑客,需要社区一起想办法

1
BodhiAlpha @happy20250912 ·

@rionaifantasy Deepfake videos can now be interactive in real time, making even "face-to-face" conversations on Zoom unreliable. The focus of attacks has now completely shifted from code vulnerabilities to "people." Once the agent gains execution rights, message injection can directly transform into on-chain transfers…

original · zh

@rionaifantasy 深伪视频已经能实时互动,Zoom里“当面”对谈都不可信了。 现在攻击重心从代码漏洞彻底转向“人”,Agent再一拥有执行权,提示词注入直接变链上转账……

1
秋蝶🌸 @RitaDanielbdxh ·

@rionaifantasy I bet nobody's more adventurous than me 🏆🐬 I'm not shady, you'll see!

original · zh

@rionaifantasy 应该没人比我玩的开了吧🏆🐬 我福不黑不信你看

飞柏🌸 @HarrietPul3tdu ·

@rionaifantasy I bet nobody's more adventurous than me 🥇😁 I'm not shameless, you'll see!

original · zh

@rionaifantasy 应该没人比我玩的开了吧🥇😁 我福不黑不信你看

冰菱🌸 @JodieGossee976 ·

@rionaifantasy I'm so lewd 🌸🥊 Anyone want to give a sharp critique of my luck?

original · zh

@rionaifantasy 我果然太涩了🌸🥊有人想锐评一下我的福嘛