Viral AI Agent Instinct Raises $2.5 Billion Amid Severe Security Warnings
AI startup Instinct has raised $350 million at a $2.5 billion valuation while gaining viral traction in Israel. However, security experts warn of aggressive data permissions, prompt injection vulnerabilities, and privacy risks.

An experimental personal AI agent known as Instinct has rapidly captured significant attention in Israel's tech community, sparking massive interest, extensive waitlists, and viral social media discussions regarding its automation capabilities. Reports from late August indicate that the AI startup has already raised $350 million at a $2.5 billion valuation, even before opening its product to the general public.
How Instinct Operates and Industry Backing
Instinct functions as an autonomous agent that integrates deeply with a user's digital ecosystem, connecting directly to email, messaging platforms, calendars, audio files, location services, and active device screens. Users can interact with the agent via SMS or WhatsApp, assigning complex daily tasks such as booking appointments, arranging transportation to the airport, organizing messy inboxes, scheduling travel, purchasing groceries, and searching for affordable flights.
According to corporate filings in California and terms of service documentation, the operating entity behind Instinct is Spear Street Technology based in San Francisco, which PitchBook notes has largely operated under the radar. The company is led by Noah Shinn, a former researcher at Sierra who is only 23 years old, according to reports by The Wall Street Journal.
«I’m excited about everything our early users are doing with Instinct. They told us they planned cross-country trips, bought weekly groceries and concert tickets, and canceled subscriptions worth hundreds of dollars. Someone is even planning their wedding with Instinct,» wrote the founder on X.
Viral Adoption and Local Use Cases in Israel
In Israel, the conversation around Instinct surged after tech figures shared examples of hyper-localized tasks. In a screenshot shared on X by Yaniv Presler, an AI integration consultant, the agent was asked whether it could obtain login credentials for Lupa, access stored family photos from a child's Bar Mitzvah, and generate a top-tier physical photo album.
Instinct enthusiastically replied, "Now you're talking. This is exactly the task I exist for," adding that it would access Lupa, upload the images, select the strongest shots, design the album page by page, and present a preview before any order or payment is placed. The agent also requested the storage location of the photos, clarifying that login credentials must not be sent directly via chat but through a secure link.
Security Risks, Privacy Concerns, and Vulnerabilities
However, this wave of enthusiasm is accompanied by severe security warnings. According to TechCrunch, users widely circulated screenshots of the company's terms of service, which grant Instinct broad, "perpetual and irrevocable" licenses to access, store, duplicate, transfer, display, publish, distribute, and modify user materials—including utilizing them for AI model training.
The terms also state that Instinct can ingest data from user devices, including screenshots, cursor movements, and keystrokes, as well as enter into binding agreements, commitments, or financial transactions on behalf of users.
Security experts have sounded the alarm. Uri Eliabayev, a prominent AI specialist, stated:
«One of the reasons I haven't tried Instinct or OpenClaw or any similar product is security issues. No matter how amazing the technology is, I won't take the risk of data leakage or service lockouts, especially when it involves my WhatsApp. I prefer to wait a bit rather than take this risk.»
TechCrunch highlighted a series of security flaws reported by early users. Peter Yang noted that Instinct initially failed to delete Gmail logs upon request, though the team later resolved the issue using an external data deletion tool. Claire Wu discovered that Instinct continued summarizing her inbox even after she revoked its permissions; when queried, the bot confirmed that emails were retained as plain text for future search indexing.
Another user expressed alarm when Instinct retrieved a verification code directly from their inbox to complete a restaurant reservation via Resy through the platform. Alex Cohen, co-founder of Hello Patient, reported deleting his account after realizing how vulnerable personal agents are to prompt injection and phishing tactics. Katie Jacobs Stanton, founder of Moxxie Ventures, stated that Instinct shattered her trust by dispatching an email on her behalf without prior confirmation.
Following initial media inquiries, the company told The Wall Street Journal that it takes emerging security concerns seriously and announced a $2.5 billion valuation backed by a $250 million Series B funding round led by Index Ventures and Benchmark, alongside prior investments from Kleiner Perkins and Conviction.
Expert Perspectives on Agentic Security
Eli Samdja, director of the research department at Check Point, warned about the systemic dangers of autonomous AI assistants:
«We need to look at an AI assistant almost like an additional user inside our account. If it has access to email, files, financial data, or other applications, any attacker who successfully manipulates the agent will find themselves holding a 'master key' that grants access to all these resources.»
Samdja explained that risks are amplified because agents consume external content from websites, documents, and emails that may contain hidden malicious prompt injections designed to hijack execution flows. He emphasized that the principle of least privilege is paramount: users must grant assistants only the minimal required access and ensure critical actions require explicit multi-step confirmation.
Meta Enters the Personal Agent Market with Muse
Amid these developments, Meta announced the launch of Muse, its own personal AI agent, initially rolling out in the United States. Designed to handle daily tasks and complex workflows—such as sending emails, booking rides, filling out forms, and breaking down large projects into actionable steps—Muse operates through a dedicated app or directly via WhatsApp.
Meta noted that Muse features persistent memory to tailor assistance across sessions—such as turning an Instagram Reel recipe into a grocery store list while factoring in dietary restrictions—and operates within a secure runtime environment known as Muse Secure VM, ensuring that passwords and payment details remain protected.





