BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
AI

Security Firm Zenity Says It Cracked Every Major Agentic Browser With Zero Clicks

Researchers describe a technique called PleaseFix that reportedly hijacks AI-driven browsers without any user interaction.

Original AltcoinGordon illustration for: Security Firm Zenity Says It Cracked Every Major Agentic Browser With Zero Clicks
Original illustration, drawn for this story by AltcoinGordon.

Zenity, a cybersecurity research firm, has demonstrated what it describes as a zero-click takeover of every major agentic browser currently on the market. The finding was reported by Forkast on August 8, 2026, and centers on a technique the researchers have named PleaseFix.

Agentic browsers are a newer category of software. They pair traditional web browsing with AI agents capable of clicking, filling forms, and completing tasks autonomously. Users increasingly rely on these tools to automate research, shopping, and even financial actions without manual input.

A zero-click exploit requires no action from the victim. Unlike phishing links or malicious downloads that need a user to click something, a zero-click attack can compromise a system purely through exposure. That makes this class of vulnerability especially difficult to defend against, since standard user caution offers little protection.

Zenity's demonstration reportedly shows that this weakness is not limited to one product. The firm says it affects every major agentic browser it tested, suggesting a shared architectural issue rather than an isolated bug. Details on the exact mechanism, affected vendors, and disclosure timeline were not included in the available reporting.

The implications extend beyond conventional web browsing. Agentic browsers are increasingly pitched as tools for crypto users who want AI assistants to manage portfolios, execute trades, or interact with decentralized applications. Any browser-level compromise in that context could expose wallet connections, exchange sessions, or signing permissions to unauthorized control.

The crypto industry has spent years hardening wallet security against phishing, malicious smart contracts, and browser extension exploits. A zero-click vulnerability in the browser layer itself would represent a different kind of threat. It could bypass many of the safeguards users currently depend on, since those defenses generally assume some form of user interaction triggers the compromise.

Zenity's naming of the technique, PleaseFix, appears to signal urgency toward affected vendors rather than describe a formal designation. As with early-stage security disclosures, the full scope of impact and any vendor responses may become clearer as more details emerge.

Market Impact

For crypto markets specifically, the concern centers on custody and transaction security rather than token prices. Agentic browsers that hold session access to exchanges, wallets, or DeFi interfaces could become attractive targets if a zero-click flaw is confirmed across platforms. Traders and platforms that have adopted AI browsing agents for automated execution may face pressure to pause or restrict such integrations until vendors respond.

Broader market reaction is likely to be limited unless a specific exchange, wallet provider, or custodial service confirms exposure. Security researchers frequently disclose vulnerabilities before patches are available, and the actual risk to funds depends on how quickly affected companies respond.

The report underscores a growing tension between convenience and security as AI agents take on more autonomous control over browsing and financial tasks. Further details from Zenity or affected vendors will help clarify how serious the exposure is and how quickly it can be addressed.

Frequently Asked Questions

What is a zero-click exploit?

It is a type of attack that compromises a device or account without requiring the victim to click a link, open a file, or take any action.

What is an agentic browser?

It is a web browser built with an AI agent that can independently complete tasks like clicking, filling forms, and navigating sites on a user's behalf.

Why does this matter for crypto users?

Some agentic browsers are used to manage wallets, trades, or DeFi interactions, so a browser-level vulnerability could expose those financial connections to unauthorized access.

Has this vulnerability been confirmed by browser vendors?

The available reporting attributes the finding to Zenity's demonstration, and it is not yet clear how affected vendors have responded.