Bitcoin ETF Comeback: $2.4B Week Flips Year-to-Date Flows Positive
Michael Saylor Calls for ‘Bill of Digital Rights’ for AI…
Bitget freezes XRP withdrawals as 27M stolen tokens move
California Governor Gavin Newsom signs law banning public officials from...
Peter Brandt Says XRP Charts Alone Give Him Reason to Make a Bet
Investigation Links $18 Million Rug-Pull Scheme to 53 Token Launches on Robinhood Chain
Wazz: 53 Robinhood Chain Token Launches Linked to Rug-Pull Operation, at Least $18.43M...
Bitcoin Price Analysis: Key Support Levels and Liquidity Clusters to Watch This Week
Strategy Turns to Daily Dividends to Steady Its Preferred Stocks
SEC staff’s staking-token split spotlights the exit risks behind staked ETH tokens
Global Money Supply Hits Record $103.66 Trillion
Ripple News: Why Ripple’s CLO Says CLARITY Act’s Fate Doesn’t Matter For XRP
Zano restarts blockchain and rolls back a month of history to fix unauthorized ZANO and fUSD...
Zano Wipes 1 Month of History to Fix Massive Crypto Inflation Bug
Apollo Chief Economist Warns AI Agents Could Trigger Bank Runs
When Will Nvidia Stock Go Down? Here’s What Could Trigger It
AI Agents Keep Escaping Their Creators' Control—Here's What We Know
New Bitcoin proposal rescues locked multisig wallets – At a hidden cost
Visa cuts reported stablecoin volume but there’s no proof payments fell
Peter Brandt Predicts $8,600 ETH, Coinbase Adds IPO Share Trading, And More – Week In Review
SpaceX/cursor_ai’S benln SAYS THAT fomo IS THE FASTEST GROWING STARTUP ON X BY FOLLOWER...
Strive CEO Indicates Plans to Expand Bitcoin Holdings
Vitalik Buterin Unveils Ethereum's Vision for 2030
U.S. President Trump Anticipates Further Negotiations with Iran
Vitalik Buterin says Ethereum is called a "blockchain" mostly "for historical reasons"
Bitget Hacker Moves $83M in XRP as Network Rules Limit…
Ripple Price Analysis: XRP Tests Critical Resistance as Bullish Structure Holds
Vitalik publishes 32-chapter work "Snowmoon," open-sourced under GPL v3
Kraken Parent Payward Bets Billions to Become Financial Infrastructure
Bybit's weekly platform updates General• $PONS is officially listed on Bybit Spot• Tomorrowland...
Bitcoin's Quantum Problem: Three Ways Researchers Are Trying to Fix It
Vitalik Buterin Releases Science Fiction Novel 'Snowmoon' Under Open Source License
Bitmine Chairman Highlights Role of Tokenization and AI in Cryptocurrency Market Cycle
THORChain Rejects Bitget's Request to Block Hacker Addresses
Ethereum's Future Vision Focuses on Censorship Resistance and Wallet Flexibility
Bitcoin Surges 32% Over Two Months, Still Below Year-Ago Prices
Vitalik Buterin maps Ethereum’s shift beyond a blockchain in sweeping 2030 vision
US Treasury Secretary Bessent: Core inflation has remained calm
Even More Orange: Saylor Teases Another Strategy Bitcoin Buy
Jupiter Exchange COO Advocates for Major Improvements in DeFi to Attract Institutional Capital
Ethereum is not instant, but collateral could make it feel that way
Bitcoin Price Climbs Back Toward $85K With Bulls in the Driver’s Seat
Monochrome Exchange Raises Over 5.5 Million USDT in MCR Token IEO
U.S. Bitcoin ETFs Draw $2.4 Billion as 2026 Net Flows Turn…
Vitalik Buterin Envisions Ethereum as a 'Cryptographic World Computer'
Trader 0x9c6a opened a 20x long on 550,087 $SOL ($67.88M) a month ago and is now sitting on an...
Vitalik: Ethereum Is Evolving Beyond a Blockchain Into a “Cryptographic World Computer” Vitalik...
Monochrome Exchange, founded by former Binance Australia CEO, launches MCR IEO with over 5.5 million USDT raised
DYORSWAP Announces Compensation Plan for Affected Users
SEC Staff Says Token Buybacks Don't Make Crypto a Security—If the Network Works
Bad News Is Good News — Week in Review
DOGE Rally Brewing? Whales Load Up as Dogecoin ETFs Post Record Inflows
Market Overview: BTC : $84824 ETH : $2708.78 BNB : $780.73 SOL : $123.55 Market Cap :Total : 2.9T DeFi ...
Kalshi Loses Again as Sixth Circuit Lets States Regulate Its Sports Contracts
DYORSWAP: Compensation Plan for GIWA Fake Chain Scam Released
Monochrome Exchange (@Monochrome_EN), founded by Jeff Yew (@jeffyew_), co-founder and former CEO of...
From Tokyo To Washington, Bond Yields Are Breaking Records
Bitcoin Price Prediction For October: One Level Stands Between Rally And Reversal
Ethereum Introduces Decoupled Consensus Protocol for Faster Transaction Finality
French investigators probe alleged Verasity VRA token manipulation and €50M Dubai real...
Bitcoin 7-day average hashrate drops to three-week low as miners shift to AI computing
Senate stalls Digital Asset Market Clarity Act after months of bipartisan negotiations...
Amazon Stock Could Hit $1,000 by 2036, Forecast Shows
Michael Saylor Hints at Increased Bitcoin Holdings with New Bitcoin Tracker Update
How months of work on the Clarity Act all fell apart
QNT Leads Altcoin Rally, BTC Price Aims at $85K Again: Weekend Watch
Prediction markets promised better information and hired Hollywood
US Senator Lummis: The Clarity Act rejected by Democrats had empowered the Treasury to combat money laundering through offshore exchanges
SEC’s Hester Peirce Wants Zero-Knowledge Proofs to Fix KYC System
Meta Opened Free Access to Muse AI Agent with 100M Tokens per Week
- Meta has launched the personal AI agent Muse.
- It can independently carry out user tasks, with access to email, a browser, and services.
- In addition, the company promised $300,000 for finding vulnerabilities in the AI agent.
Meta has unveiled Muse — a personal AI agent that can work with email, a calendar, a browser, and other connected services, completing user tasks in the background.
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.
— Mark Zuckerberg (@finkd) September 8, 2026
According to Meta founder Mark Zuckerberg, Muse was built with a focus on privacy and security: the agent runs in a dedicated cloud virtual machine, and all actions involving external services are controlled by a separate Sentinel agent.
The company positions the product as a step toward “personal superintelligence” and made it free within a limit of up to 100 million tokens per week.
The project has been developed and used internally at Meta since early 2026. The team notes that while working with Muse, it saw the first signs of “real personal superintelligence” — a system that can know the user, independently complete tasks, run in the background, spin up groups of sub-agents, create its own tools, and even edit itself.
Muse became the first case where developers allowed an AI agent to work unsupervised with their own mailboxes, calendars, and command line. That is why Meta dedicated a significant part of the development to limiting the potential consequences of mistakes and attacks.
After Meta unveiled Muse Spark — the first model in the new family — the company continued developing it as a foundation for agentic use cases.
Muse uses the Muse Spark 1.3 model, which Meta is training with a focus on tool calls via the CLI and skills, long-context and long-horizon action sequences, resistance to prompt injection, and coordination across multiple agents.
How Meta Protected Muse From Attacks
The core principle of Muse’s architecture is that the agent does not get unrestricted access to the user’s computer or credentials. A separate cloud Linux virtual machine is created for each user, with a browser, CPU, memory, and storage, where the data and credentials of connected services are stored.

The agent itself runs inside an isolated environment, while critical security components sit outside it. Specifically:
- Hatch — an agent runtime that runs in an isolated container and executes code, tools, and file operations
- hatch-safety — an independent set of models and classifiers for checking prompts, responses, and potential attacks
- privsep — executes embedded connector code with strictly limited privileges
- hatch-authd — responsible for securely storing credentials and tokens
- Sentinel — the only component that can allow or block actions via third-party services and outbound network traffic
Sentinel plays a key role. Muse can propose performing a certain action, but the final decision on access to a third-party service is made by Sentinel. Depending on the policy set by the user, it can allow the action, reject it, or ask for user confirmation.
This mechanism also applies to network requests. Sentinel checks the destination address, IP, port, protocol, HTTP method, path, and the actual contents of the request. For operations that require secrets, the system uses surrogate tokens: Muse never receives the real password or API key, and the real credentials are added to the request only at the network boundary after it is authorized.
Meta also uses a “tainted egress” mechanism that tracks whether a process has had access to user data. If such a process tries to send information outside, it loses the ability to execute the request automatically and falls back to the standard confirmation flow.
Separately, the company focused on prompt injection attacks, where malicious instructions can reach the model via emails, web pages, files, or other data. Meta uses several layers of protection:
- Training the model itself to recognize and reject prompt injection
- Labeling external data as untrusted in the model’s context
- An ensemble of independent classifiers to detect attacks
- Agentic red teaming on external data
- Human confirmation before actions that move data outside the virtual machine
- System-level restrictions that remain in effect even if the model is compromised
Meta said that Muse Spark 1.3 is close to state of the art (SOTA) in its ability to withstand prompt injection.
Browser, Shopping, and Privacy
Muse got a Chromium-based browser where the user can see the agent’s actions and take over control at any time. The browser sub-agent runs through a separate broker, and it does not have access to the full DOM, JavaScript, or Chrome DevTools.
Meta also uses additional classifiers to detect prompt injection, data exfiltration attempts, malicious files, and high-risk forms.
When shopping, Muse asks for confirmation every time on the checkout page if payment details are already saved on the site. For new sites, the agent can use a separate wallet, and at launch Meta is working with Stripe Link and plans to add Shop Pay.
Payments are processed via a single-use card number tied to a specific merchant, amount, and limited validity period.
The user decides which services Muse can access, and can revoke that access at any time. For email, the agent does not receive one-time codes, password reset links, or “magic” sign-in links.
At the same time, Meta acknowledges that prompt injection remains an “open industry problem,” so Muse’s architecture is designed to minimize the impact of mistakes.
Alongside the launch, Meta introduced rewards for researchers with payouts of up to $300,000, including up to $130,000 for a successful instruction-substitution attack that affects a single user.
The company is also developing Muse Confidential VM, which is intended to cryptographically protect data even from Meta itself. The technology is already being tested by a limited group of users, and its architecture and code are being reviewed by external auditors.
Muse data and files are stored in the user’s virtual machine, while credentials are kept in a separate isolated container. Meta says this data is not shared with ad systems, although the agent’s actions on the internet may indirectly influence advertising.
Dialogs and data about Muse’s operation may be used to train models after personal information is removed, and users can opt out of such use; the base plan includes up to 100 million tokens per week for free.
Recall that Muse Spark 1.1 recently went online and hacked the systems of an unknown company.
Сообщение Meta Opened Free Access to Muse AI Agent with 100M Tokens per Week появились сначала на INCRYPTED.
Source: Incrypted

