Coinbase’s AI Coding Tool Vulnerable to New Exploit
- A new exploit, termed the “CopyPasta License Attack,” can inject hidden instructions into developer files.
- The attack primarily targets Cursor, an AI coding tool used by all Coinbase engineers.
- Coinbase CEO Brian Armstrong noted that up to 40% of the exchange’s code is AI-generated, aiming for 50% by next month.
- The exploit allows malicious payloads to spread through files without direct user input, evading traditional malware detection.
- Security experts urge organizations to scan for hidden comments and manually review AI-generated changes.
The CopyPasta method enhances the risk of semi-autonomous virus propagation within coding environments, impacting multiple users simultaneously rather than targeting individuals. This poses significant challenges for cybersecurity as it exploits trusted developer workflows.
With Coinbase’s reliance on AI for a substantial portion of its code, addressing vulnerabilities like this is crucial to maintaining security in software development practices. (Source)