Leadership1 publisher3 min readPublished
Manus gives Cue agents wallets and inboxes four days after an email injection flaw
Manus gave each Cue agent its own email, phone number and wallet on Sept. 28, four days after Salt Labs disclosed an email-borne injection flaw. The reported controls cap what an obedient agent spends, while the flaw worked by getting an agent to obey an attacker's email.
The Board Room · Leadership desk

What happened
- Cue agents can send messages, take calls and leave a summary, and make payments only inside a budget the user sets.
- Manus resumed independent operations weeks before the launch, after Beijing blocked Meta's $2 billion acquisition and the two companies completed their split.
- Manus is in talks to raise $500 million at a $4 billion valuation, about twice Meta's price, and the round has not closed.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure An injected email that reached a Cue agent would have a phone line and a wallet within reach, beyond the app tokens Salt Labs got to in the older Manus environment.
- constraint A user-set budget caps what a hijacked agent could pay out, but if warnings still fire only after a payload runs, the owner learns of the loss once it has already happened.
- exposure Whoever finds the next Manus flaw has no proven route to a fix: the last one went through Meta's program, and Salt Labs said Manus itself never replied.
- decision Teams trialling Cue have to set budgets and connect accounts during early access, before Manus has said what the product will cost.
Email is where the flaw and the launch overlap. Salt Labs said an email carrying an obfuscated instruction let its researchers run code inside a victim's Manus environment [3]. Cue gives every agent an email address of its own [1]. The new Automations can start work when an email arrives [10]. The Salt Labs findings concern Manus as it stood before Cue's release, which came four days later [1].
The board-deck version is that the flaw was patched before launch [6] and that each Cue agent pays only inside a budget the user sets [2]. Computer Use limits an authorized agent to approved files, browsers and apps, in a desktop session the user can see [11]. Those controls govern an agent that is following its owner. The Salt Labs attack got the agent to follow an email instead. It reached credentials and tokens for whatever apps the victim had connected, such as Gmail, Dropbox or GitHub [4]. Manus's security warning appeared only after the payload had run [5].
Salt Labs drew its own conclusion. Yaniv Balmas, vice president of research at Salt Labs, said: "Any agentic system designer should carefully think of robust layers of defense, and not simply trust guardrails to provide all protections, just the same as we do with our traditional services." [7]
The fix came from outside the company. Salt Labs said Manus did not reply to its report, and according to implicator.ai, Meta's bug-bounty program triaged, confirmed and patched the flaw while Meta was preparing its acquisition [6]. Beijing then blocked Meta's $2 billion deal and the two companies completed their split. Weeks before the launch, Manus said it had resumed independent operations [8]. The implicator.ai report does not say who now handles vulnerability reports at Manus, or whether Cue adds a defense against instructions hidden in incoming mail.
The incentives favor shipping capability. Manus builds on Claude and Alibaba's Qwen models and does not train its own base models from scratch [12]. According to implicator.ai, Meta's Muse agent topped app store charts after its September release [13]. The same report says models including Moonshot's Kimi and Claude increasingly handle general desktop tasks as well as Manus does [16]. In my view, a company that builds on other labs' models competes on its harness and on what its agents are permitted to do. Manus's own unverified figures credit its Cascade harness with 32% lower cost in one tested configuration [14]. The company is in talks to raise $500 million at a $4 billion valuation, about twice Meta's price, and the round has not closed [9].
For a team piloting Cue, this quarter's decision is which accounts and how much money to attach to an agent. Next quarter's consequence is what an injected instruction would find there. Cue is in early access on the web, desktop and mobile, with the iOS version awaiting App Store review [15]. Each connected tool adds a route for outside text to reach an agent that can pay: Automations can also start from calendar events, Slack messages and Notion updates [10].
What to watch
- Whether Manus publishes its own vulnerability-reporting channel or bug bounty now that it has split from Meta, whose program handled the Salt Labs fix.
- Independent testing of Cue agents against email-borne prompt injection, especially through Automations that start when mail arrives.
- Cue's price after early access, and whether the $500 million round at a $4 billion valuation closes.