NGate Campaign Uses AI-Generated Code to Steal NFC Data
Threat actors needed malware capable of stealing NFC data and PINs from Android devices in Brazil. They trojanized the legitimate HandyPay application with AI-generated code that accomplished this reliably. The malware passed review faster than most internal tickets.
Severity: Unrated · Category: Tool Misuse
Impact: Theft of NFC data and PINs from users in Brazil
Source: The Hacker News · Apr 21 2026
How Fencio prevents this
The tools worked exactly as designed. The agent called them with the wrong arguments, at the wrong time, or more often than it should have, and no layer checked whether the call made sense before it ran.
Fencio validates every tool call against expected intent: argument ranges, recipients, amounts, and call frequency. Calls that fall outside expected bounds, repeat without idempotency, or touch identity and money are held for confirmation.