🟢 The Trunkline founding community is open and free. No pressure, no countdown. Join free now →

An AI Recommended a Coin That Didn’t Exist. Here’s How 15 Words Did It.

Real numbers. No hype. Receipts.

A team of researchers asked an AI research assistant to help pick investments. It came back recommending “BananaCoin” as an emerging, long-term opportunity. BananaCoin does not exist. It was planted — and it took about fifteen words to do it.

That is not a hypothetical. It is the finding of a study out of Cornell Tech, and it is the clearest reason yet for one rule we live by: when an AI tells you something about your money, verify before you trust it.

What the researchers actually did

Tingwei Zhang, Harold Triedman, and Vitaly Shmatikov of Cornell Tech published a paper (posted to arXiv on May 22, 2026) describing an attack they call WARP — Web Agent Retrieval Poisoning. The idea is simple and cheap. AI “research” tools answer your question by fetching pages from the open web — Reddit threads, forum posts, wiki pages. An attacker finds a page the tool already tends to pull, and appends a short, blended sentence written to sound like the rest of the page.

That is the whole trick. In their tests, roughly 13 to 15 words of planted text was enough to get a made-up product named in 38% to 51% of the AI’s answers — and as high as 62% when the same claim was seeded in a couple of places. The fake “BananaCoin” landed in a generated report as an emerging investment. And Reddit was the single biggest source the tools drew from — between 54% and 71% of the user-generated links they retrieved.

The honest limits — because that is the point

We are not going to oversell this. The researchers ran their live manipulation on three open-source research tools (STORM, Co-STORM, and OmniThink). They looked at the big commercial ones — OpenAI’s and Google’s deep-research modes — but deliberately did not run live attacks on them, because that would mean altering real public pages. So this is one study demonstrating a mechanism, not proof that the assistant on your phone has already been fed a lie. Treat it as what it is: a working, cheap method that targets exactly how these tools gather information.

But here is why it still matters for you. Every one of these systems — open-source or commercial — works the same basic way: it trusts the open web, and the open web is editable by anyone. A confident, well-written AI answer is not the same as a verified one. The polish is free. The truth is not.

The rule: verify before you trust — especially about money

AI assistants are increasingly the first place people ask “is this a good investment?” or “is this platform legit?” That is precisely where a planted answer does the most damage, because a fake “emerging” opportunity is exactly what a scammer wants you to hear. So, three habits that cost you nothing:

  • Trace the claim to a primary source. If an AI says a coin, fund, or company is legitimate or promising, ask who says so, on the record. The regulator’s site, the official filing, the company’s own disclosures — not a summary of a forum post.
  • Be most skeptical of “new” and “emerging.” The planted BananaCoin was sold as up-and-coming. Manufactured hype hides best in things too new to have a real record.
  • Treat AI citations to Reddit, forums, and comment threads as leads, not proof. They are the easiest surfaces on the internet to edit, and the research shows they are exactly what these tools reach for.

This is the whole reason we build the way we do: every number here is dated and traced to a primary record, and when we are wrong we log it in the open. Not because we distrust the machines — but because “the AI said so” was never a receipt. Ask for the receipt.


Sources (primary): Zhang, Triedman & Shmatikov (Cornell Tech), “Deep-Research Agents Can Be Poisoned via User-Generated Content,” arXiv, posted May 22, 2026. Reported independently by Search Engine Land and Help Net Security (June 2026). Systems live-tested: STORM, Co-STORM, OmniThink (open-source); commercial deep-research modes were analyzed, not live-attacked.

Curates public information from primary sources for education. Not investment, financial, legal, or tax advice. — Trunkline · Carter Enterprise LLC

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *


Trunkline emblem
Part of the Carter Enterprise Network
CARTER ENTERPRISE LLC
Carter Enterprise LLC · 30 N Gould St, Suite 65270, Sheridan, WY 82801
© 2026 Carter Enterprise LLC. Real numbers. No hype. Receipts. Education, not financial advice.