Leadership1 publisher3 min readPublished Updated
Investor's test shows Instinct's AI agent can read card numbers stored in its own vault
Instinct's AI agent, from a startup valued at $10bn this week, read a stored test card number and passwords back in plain text in an investor's test. For employers whose staff use personal agents, the open question this quarter is which credentials belong in an agent's vault at all.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Zhao, a partner at Informed Ventures, was told the agent could fill in a Booking.com hotel form if he saved his card in the Vault, Instinct's credential manager.
- He ran the test with a fake card number, and the agent pulled the details by running JavaScript on the booking webpage.
- Stripe can issue Meta's Muse agents single-use virtual cards capped at the approved purchase, so the agent never sees the underlying card details.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- contradiction The agent tells users it will not see card numbers directly, yet it read one back in Zhao's test, and the company's statement does not say which description is accurate.
- decision Employers setting rules for agent use now weigh a stored real card that can fill any form against a single-use virtual card limited to one approved purchase.
- precedent Meta's no-visibility assurance for Muse is the same kind of promise Instinct made, so vendor claims of this sort now carry less weight until someone tests them.
The Vault promises less than it seems to. When the agent asks for a card, it says it won't see sensitive details such as card numbers directly [3]. Yet the reason for handing the card over is so the agent can fill out the booking form [2]. I think the plain reading is that the protection covers the vault and ends at the form. Zhao's agent got the numbers back by running JavaScript on the webpage [5].
The evidence is one test by one person. Zhao used a fake card number [4], and the confirmation that the agent could see it came from the agent itself. It read the card and his passwords back to him in plain text [5]. "These companies have been doing a lot to try to protect user information and try to create a magical functionalist experience for users," Zhao said [6]. He asked, in the case of personal agents, "how should people think about security?" [7]
Instinct's reply is the case a skeptic would make. The company is backed by Sequoia Capital and raised at a $10 billion valuation this week [9]. "Securing user data is a top priority for us, and users are always in control of their data and credentials," a spokesperson said [8]. Zhao's test asked what the agent could read once the form was filled, and the agent could read it [5].
Zhao was looking up hotels on Booking.com for himself [1], and the account does not describe workplace use. The exposure for employers comes from one detail: passwords were among what the agent read back [5]. A work login saved in a personal agent's vault is within reach of that agent's scripts.
Another design is already in use. Stripe has partnered with both Meta and Instinct on agent payments [10]. For Meta's Muse, it can issue single-use virtual cards capped at the specific approved purchase [11]. The cards link to the user's Stripe Link wallet, and the agents do not see the underlying payment details [11]. The trade-off is reach. A real card in a vault can fill any form, while a single-use card covers one approved purchase. Meta has said in a blog that Muse has no visibility into people's passwords or payment methods [12]. Instinct's agent gave users a similar assurance [3], and Zhao's test ran on Instinct [1].
The payment industry's larger rebuild runs on a longer clock. "We spent 30 years building up this infrastructure that blocked all the bots," said Dan Coates, product management director at ACI Worldwide [13]. "How do we let the good ones in and block the other ones?" he said [14]. Visa and Mastercard have introduced an agent registry that verifies agents and tells them apart from bots [15]. Benzinga reports that misspending is the industry's biggest worry, and payment firms have answered it with spending caps [16]. Both tools deal with who the agent is and how much it can spend, and Zhao's test was about what the agent can read [5].
The decision for this quarter is small and specific: which credentials staff may store in a personal agent's vault. If corporate cards and work passwords go in now, the agent's scripts can read them, and the company did not choose that agent. Limiting agents to single-use virtual cards gives up the convenience of a stored card that fills any form. In exchange, spending is capped at the one approved purchase [11].
What to watch
- Whether Instinct changes how the Vault autofills credentials, or rewords the assurance its agent gives users, after Zhao's test.
- Whether anyone reproduces the plain-text readback on Meta's Muse, whose blog says it has no visibility into passwords or payment methods.
- Whether Stripe offers its purchase-capped single-use virtual cards to Instinct agents, given that it already partners with Instinct.