Bitcoin Spot ETFs Experience Continued Net Outflows
Ethereum Spot ETFs See Significant Net Inflows
Bitcoin ETFs See $13.29M Net Outflows on September 11 (ET), Extending Outflow Streak to Four Days;...
Bitcoin ETFs Experience $13 Million Outflows as Ethereum ETFs Attract $216 Million
Bitcoin ETFs Extend Outflow Streak to Four Days on September 11 (ET), While Ethereum ETFs See $216M...
Why Crypto’s Next Adoption Test Is Operational, Not Speculative
Sydney Sweeney Takes Equity in Novig for Its Viral Ad
Huobi HTX Records Net Capital Inflow of Over $446M in 24H and $438M in 7 Days, Ranking First Among Mainstream CEXs
Total Value of Tokenized Assets Reaches $346 Billion Across 47 Asset Types
WSJ: Markets Start Pricing in a Series of Fed Rate HikesAccording to The Wall Street Journal, that...
Coinbase Wallet Introduces Pulse Mode for Enhanced Perpetual Futures Trading
Tesla Stock Is Becoming Elon Musk’s AI Empire
Trump sues JPMorgan for $5B! Ledger prepares for $4B IPO! “Crypto Adoption is no longer reversible” says PWC!
Hyperliquid Burns Tokens Worth $2.65 Million in 24 Hours
From Stellar to Canton: How Franklin Templeton Adopted Tokenization
Wealth Managers Signal Crypto Shift With 60% Planning Allocations
Pump fun(@Pumpfun) sold another 77,705 $SOL ($7.88M) 6 hours ago.In total, pump.fun has sold...
Surge in Tokenized ETF Deposits into DeFi Reaches $68 Million
BitMEX Co-Founder Ben Delo Donates Record £36 Million to Reform UKBitMEX co-founder Ben Delo has...
Independent Solo Miner Successfully Mined Block 966,351, Receiving 3.147 BTC
Why Nasdaq surveillance cannot settle the fight over 24/7 tokenized markets
157,173,943 $USDT (157,134,597 USD) transferred from unknown wallet to #Binance...
Robinhood Chain Reports Significant Revenue Decline Amid Increased Activity
BitMEX Co-founder Ben Delo Donates £36 Million to UK Reform Party, Setting Record for Single Political Donation
Circle Launches Euro Stablecoin EURC on South Korean Exchange Upbit
Clearpool Targets XRP Ledger Credit Market With Token Overhaul
Morgan Stanley MSBT ETF Boosts Holdings by 51.58 BTC Amid Significant Inflows
Symbiosis Bitcoin Bridge Suspends BTC Routing Following Security Incident
L-BTC resumes trading with reserves covering just 85% of supply
A Whale Bought Over 36,000 ZEC in Six Days, Worth Approximately $41.56 Million
193,344,000 $USDC (193,296,630 USD) transferred from Unknown Whale 1 to #Aave...
US House Committee to Review Crypto Tax Legislation on September 16
KLEA Crypto Daily: Friday, September 11, 2026
745 $BTC (57,550,174 USD) transferred from #Coinbase to unknown wallet...
Nvidia in Talks to Invest in Anthropic's IPO Project, Up to $10 Billion
Crypto Fear and Greed Index Index Value : 63 Sentiment : Greed BTC Price : $77209 ...
pointfarmcap FLIPS theunipcs FOR #1 ALL-TIME PNL ON fomo ...
US Bank moves USBDC across borders on Stellar, but only inside its own walls
Apollo Global Management Winds Down Certain Products at Eliant Trade Finance Platform
811 $BTC (62,580,323 USD) transferred from unknown wallet to #Coinbase...
Robinhood CEO says companies shouldn't get veto over stock tokens in AMC feud
CFTC Implements Automatic 30% Whistleblower Awards for Cases Under $5 Million
Solo Bitcoin Miner Hits $244K Jackpot After Nearly 40-Day Drought
193,344,315 $USDC (193,340,448 USD) transferred from #Aave to Unknown Whale 1...
Mecka AI Approaches $500 Million Valuation in Sequoia Capital Funding Round
UniCredit Explores Crypto Custody and Brokerage…
Ethereum Re-enters Global Top 100 Assets by Market Capitalization
Ethereum Targets October 6 for Glamsterdam Sepolia Fork
Banks get cross-exchange crypto hedge relief under Canada’s new 2027 capital rule
Kalshi Seeks Approval for Perpetual Futures on Major U.S. Stocks
Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
Solana Tokenized Stocks Hit Record $684M as Trading Surges
Ripple Is Putting AI Agents Into the $1 Billion Treasury…
Harvey Launches AI-Powered Contract Review Agents for Legal Teams
Binance Research: Tokenized Stocks Shift From Issuance to Distribution and UsageBinance Research...
Strategy Inc. Reports Strong Performance Amid Market Gains
Nasdaq to Launch Tokenized Stocks with Shareholder Rights by 2027
GPT-5.6 Sol Automates Quantum Experiments at MIT
Coinbase CEO sees Bitcoin at $400,000, but first it has to clear $81,000
Cyberattacks on Law Firms Nearly Double as Stolen Documents Hit the Dark Web
Cantor Fitzgerald Raises Bitmine Price Target to $63.60 Amid Ethereum Strategy Shift
999 $BTC (77,321,320 USD) transferred from #Coinbase to unknown wallet...
ETH Price Surges Past $2,600 as CPI Data Triggers Squeeze
1,045 $BTC (80,821,245 USD) transferred from unknown wallet to #Coinbase...
DOGE Facing Uncertainty After Bitwise Orders Shutdown Of Dogecoin ETF; Here’s Why
Former Alameda Research CEO Caroline Ellison has a new job at 501c3 charity Manifund,
🏴 Robinhood Chain's Hidden Gems?
Metaplanet Cuts Management Equity Reward Pool by 41% After…
2,130 $BTC (164,882,755 USD) transferred from unknown wallet to #Coinbase...
Meta Opened Free Access to Muse AI Agent with 100M Tokens per Week
- Meta has launched the personal AI agent Muse.
- It can independently carry out user tasks, with access to email, a browser, and services.
- In addition, the company promised $300,000 for finding vulnerabilities in the AI agent.
Meta has unveiled Muse — a personal AI agent that can work with email, a calendar, a browser, and other connected services, completing user tasks in the background.
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.
— Mark Zuckerberg (@finkd) September 8, 2026
According to Meta founder Mark Zuckerberg, Muse was built with a focus on privacy and security: the agent runs in a dedicated cloud virtual machine, and all actions involving external services are controlled by a separate Sentinel agent.
The company positions the product as a step toward “personal superintelligence” and made it free within a limit of up to 100 million tokens per week.
The project has been developed and used internally at Meta since early 2026. The team notes that while working with Muse, it saw the first signs of “real personal superintelligence” — a system that can know the user, independently complete tasks, run in the background, spin up groups of sub-agents, create its own tools, and even edit itself.
Muse became the first case where developers allowed an AI agent to work unsupervised with their own mailboxes, calendars, and command line. That is why Meta dedicated a significant part of the development to limiting the potential consequences of mistakes and attacks.
After Meta unveiled Muse Spark — the first model in the new family — the company continued developing it as a foundation for agentic use cases.
Muse uses the Muse Spark 1.3 model, which Meta is training with a focus on tool calls via the CLI and skills, long-context and long-horizon action sequences, resistance to prompt injection, and coordination across multiple agents.
How Meta Protected Muse From Attacks
The core principle of Muse’s architecture is that the agent does not get unrestricted access to the user’s computer or credentials. A separate cloud Linux virtual machine is created for each user, with a browser, CPU, memory, and storage, where the data and credentials of connected services are stored.

The agent itself runs inside an isolated environment, while critical security components sit outside it. Specifically:
- Hatch — an agent runtime that runs in an isolated container and executes code, tools, and file operations
- hatch-safety — an independent set of models and classifiers for checking prompts, responses, and potential attacks
- privsep — executes embedded connector code with strictly limited privileges
- hatch-authd — responsible for securely storing credentials and tokens
- Sentinel — the only component that can allow or block actions via third-party services and outbound network traffic
Sentinel plays a key role. Muse can propose performing a certain action, but the final decision on access to a third-party service is made by Sentinel. Depending on the policy set by the user, it can allow the action, reject it, or ask for user confirmation.
This mechanism also applies to network requests. Sentinel checks the destination address, IP, port, protocol, HTTP method, path, and the actual contents of the request. For operations that require secrets, the system uses surrogate tokens: Muse never receives the real password or API key, and the real credentials are added to the request only at the network boundary after it is authorized.
Meta also uses a “tainted egress” mechanism that tracks whether a process has had access to user data. If such a process tries to send information outside, it loses the ability to execute the request automatically and falls back to the standard confirmation flow.
Separately, the company focused on prompt injection attacks, where malicious instructions can reach the model via emails, web pages, files, or other data. Meta uses several layers of protection:
- Training the model itself to recognize and reject prompt injection
- Labeling external data as untrusted in the model’s context
- An ensemble of independent classifiers to detect attacks
- Agentic red teaming on external data
- Human confirmation before actions that move data outside the virtual machine
- System-level restrictions that remain in effect even if the model is compromised
Meta said that Muse Spark 1.3 is close to state of the art (SOTA) in its ability to withstand prompt injection.
Browser, Shopping, and Privacy
Muse got a Chromium-based browser where the user can see the agent’s actions and take over control at any time. The browser sub-agent runs through a separate broker, and it does not have access to the full DOM, JavaScript, or Chrome DevTools.
Meta also uses additional classifiers to detect prompt injection, data exfiltration attempts, malicious files, and high-risk forms.
When shopping, Muse asks for confirmation every time on the checkout page if payment details are already saved on the site. For new sites, the agent can use a separate wallet, and at launch Meta is working with Stripe Link and plans to add Shop Pay.
Payments are processed via a single-use card number tied to a specific merchant, amount, and limited validity period.
The user decides which services Muse can access, and can revoke that access at any time. For email, the agent does not receive one-time codes, password reset links, or “magic” sign-in links.
At the same time, Meta acknowledges that prompt injection remains an “open industry problem,” so Muse’s architecture is designed to minimize the impact of mistakes.
Alongside the launch, Meta introduced rewards for researchers with payouts of up to $300,000, including up to $130,000 for a successful instruction-substitution attack that affects a single user.
The company is also developing Muse Confidential VM, which is intended to cryptographically protect data even from Meta itself. The technology is already being tested by a limited group of users, and its architecture and code are being reviewed by external auditors.
Muse data and files are stored in the user’s virtual machine, while credentials are kept in a separate isolated container. Meta says this data is not shared with ad systems, although the agent’s actions on the internet may indirectly influence advertising.
Dialogs and data about Muse’s operation may be used to train models after personal information is removed, and users can opt out of such use; the base plan includes up to 100 million tokens per week for free.
Recall that Muse Spark 1.1 recently went online and hacked the systems of an unknown company.
Сообщение Meta Opened Free Access to Muse AI Agent with 100M Tokens per Week появились сначала на INCRYPTED.
Source: Incrypted

