FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.7T +0.1%24h Vol $105.4B -4.5%Fear & Greed 63/100Alts Index 35/100
BTC.D 58.3% -0.1%Stable.D 10.0% 0%ETH.D 11.5% 0%Others.D 20.2% +0.1%
牛来$0.1360+74.38%STONK$0.2971+70.94%AI$0.2519+36.56%MINA$0.1070+18%APEPE$0.00000167+15.65%CHZ$0.0153+11.72%THETA$0.1920+7.68%XCN$0.00436589+7.68%BTW$0.5004+6.3%GENIUS$0.3049+5.58%
LAPTOP$0.3526-54.09%FF$0.1493-11.39%AKE$0.0145-9.22%BP$0.5307-7.66%MARSCOIN$0.1134-7.57%ATOM$1.639-7.57%EGLD$4.475-7.31%DOT$1.051-7.18%UAI$0.6693-6.85%STABLE$0.0276-6.5%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Meta Opened Free Access to Muse AI Agent with 100M Tokens per Week

      • Meta has launched the personal AI agent Muse.
      • It can independently carry out user tasks, with access to email, a browser, and services.
      • In addition, the company promised $300,000 for finding vulnerabilities in the AI agent.

      Meta has unveiled Muse — a personal AI agent that can work with email, a calendar, a browser, and other connected services, completing user tasks in the background. 

      According to Meta founder Mark Zuckerberg, Muse was built with a focus on privacy and security: the agent runs in a dedicated cloud virtual machine, and all actions involving external services are controlled by a separate Sentinel agent. 

      The company positions the product as a step toward “personal superintelligence” and made it free within a limit of up to 100 million tokens per week.

      The project has been developed and used internally at Meta since early 2026. The team notes that while working with Muse, it saw the first signs of “real personal superintelligence” — a system that can know the user, independently complete tasks, run in the background, spin up groups of sub-agents, create its own tools, and even edit itself.

      Muse became the first case where developers allowed an AI agent to work unsupervised with their own mailboxes, calendars, and command line. That is why Meta dedicated a significant part of the development to limiting the potential consequences of mistakes and attacks.

      After Meta unveiled Muse Spark — the first model in the new family — the company continued developing it as a foundation for agentic use cases. 

      Muse uses the Muse Spark 1.3 model, which Meta is training with a focus on tool calls via the CLI and skills, long-context and long-horizon action sequences, resistance to prompt injection, and coordination across multiple agents.

      How Meta Protected Muse From Attacks

      The core principle of Muse’s architecture is that the agent does not get unrestricted access to the user’s computer or credentials. A separate cloud Linux virtual machine is created for each user, with a browser, CPU, memory, and storage, where the data and credentials of connected services are stored.

      Muse’s protection mechanism against attacks. Source: Meta

      The agent itself runs inside an isolated environment, while critical security components sit outside it. Specifically:

      • Hatch — an agent runtime that runs in an isolated container and executes code, tools, and file operations
      • hatch-safety — an independent set of models and classifiers for checking prompts, responses, and potential attacks
      • privsep — executes embedded connector code with strictly limited privileges
      • hatch-authd — responsible for securely storing credentials and tokens
      • Sentinel — the only component that can allow or block actions via third-party services and outbound network traffic

      Sentinel plays a key role. Muse can propose performing a certain action, but the final decision on access to a third-party service is made by Sentinel. Depending on the policy set by the user, it can allow the action, reject it, or ask for user confirmation.

      This mechanism also applies to network requests. Sentinel checks the destination address, IP, port, protocol, HTTP method, path, and the actual contents of the request. For operations that require secrets, the system uses surrogate tokens: Muse never receives the real password or API key, and the real credentials are added to the request only at the network boundary after it is authorized.

      Meta also uses a “tainted egress” mechanism that tracks whether a process has had access to user data. If such a process tries to send information outside, it loses the ability to execute the request automatically and falls back to the standard confirmation flow.

      Separately, the company focused on prompt injection attacks, where malicious instructions can reach the model via emails, web pages, files, or other data. Meta uses several layers of protection:

      • Training the model itself to recognize and reject prompt injection
      • Labeling external data as untrusted in the model’s context
      • An ensemble of independent classifiers to detect attacks
      • Agentic red teaming on external data
      • Human confirmation before actions that move data outside the virtual machine
      • System-level restrictions that remain in effect even if the model is compromised

      Meta said that Muse Spark 1.3 is close to state of the art (SOTA) in its ability to withstand prompt injection.

      Browser, Shopping, and Privacy

      Muse got a Chromium-based browser where the user can see the agent’s actions and take over control at any time. The browser sub-agent runs through a separate broker, and it does not have access to the full DOM, JavaScript, or Chrome DevTools. 

      Meta also uses additional classifiers to detect prompt injection, data exfiltration attempts, malicious files, and high-risk forms.

      When shopping, Muse asks for confirmation every time on the checkout page if payment details are already saved on the site. For new sites, the agent can use a separate wallet, and at launch Meta is working with Stripe Link and plans to add Shop Pay. 

      Payments are processed via a single-use card number tied to a specific merchant, amount, and limited validity period.

      The user decides which services Muse can access, and can revoke that access at any time. For email, the agent does not receive one-time codes, password reset links, or “magic” sign-in links. 

      At the same time, Meta acknowledges that prompt injection remains an “open industry problem,” so Muse’s architecture is designed to minimize the impact of mistakes.

      Alongside the launch, Meta introduced rewards for researchers with payouts of up to $300,000, including up to $130,000 for a successful instruction-substitution attack that affects a single user. 

      The company is also developing Muse Confidential VM, which is intended to cryptographically protect data even from Meta itself. The technology is already being tested by a limited group of users, and its architecture and code are being reviewed by external auditors.

      Muse data and files are stored in the user’s virtual machine, while credentials are kept in a separate isolated container. Meta says this data is not shared with ad systems, although the agent’s actions on the internet may indirectly influence advertising. 

      Dialogs and data about Muse’s operation may be used to train models after personal information is removed, and users can opt out of such use; the base plan includes up to 100 million tokens per week for free.

      Recall that Muse Spark 1.1 recently went online and hacked the systems of an unknown company.

      Сообщение Meta Opened Free Access to Muse AI Agent with 100M Tokens per Week появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud