Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts



Data breaches at two shipping companies has put cryptocurrency owners with physical hardware wallets at greater risk of having their funds stolen, highlighting weaknesses in the broader tech ecosystem relied on by the crypto industry. In recent weeks, makers of hardware crypto wallets Trezor and SafePal reported that collectively thousands of their customers had their personal data and shipping information stolen during separate data breaches at their shipping partners. The crypto wallet makers provided their customers’ names, home addresses, email addresses, and phone numbers to the shipping companies for mailing out their hardware wallets. The hacks did not affect the security of the wallets, a hardware device that stays offline that makes it far more difficult for hackers to compromise from over the internet. Instead the hackers targeted the broader supply chain of tech companies to obtain personal information about where high-net worth crypto holders live. By stealing the names and home addresses of hardware wallet customers, the hacks expose crypto owners to physical attacks that rely on physically obtaining the seed phrase stored on the wallet by force or violence. Known as wrench attacks (referring to the use of weapons), these kinds of real-world attacks are on the rise as criminals increasingly seek out crypto belonging to high-net individuals. Blockchain security company CertiK confirmed dozens of reported wrench attacks during 2025, up by 75% on the previous year, with robbers stealing upwards of $40 million. Crypto forensics giant Chainalysis puts this year’s figures at closer to $30 million so far, with gangs using kidnapping and home invasions to demand a person’s crypto seed phrase. With knowledge of a person’s seed phrase, the attackers can irreversibly take control of the person’s crypto on the public blockchain. Both Trezor and SafePal also warned customers to stay vigilant against phishing attacks, which rely on sending targeted messages to a person’s phone number or email address in an attempt to steal their crypto. In a separate attack on a hardware wallet earlier this month, hackers stole more than $130 million in cryptocurrency directly off the blockchain by guessing the passwords set by Coinkite’s Coldcard hardware wallet. The hackers, who have not yet been identified, were able to predict the seed phrases that Coldcard wallets would generate offline for their customers. Even though the wallets and seed phrases never touched the internet, the hackers were able to generate customer wallet passwords on the fly and pluck their funds directly off of the blockchain. One victim said in a post on X that they had done “everything right,” but that “none of it mattered… all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.” When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at . View Bio

The FBI has been using hacking techniques and tools, such as spyware, since at least 1998, but to date there is no public data counting how often the feds were deploying them. That’s about to change — at least for the use of spyware for tapping into someone’s real-time communications. Starting in 2029, U.S. judiciary will publicly disclose precisely how many times judges authorized the use of wiretaps to be carried out with hacking tools and spyware, which fall under the category of what the feds call network investigating techniques, or NITs. For almost two decades, the Administrative Office of the U.S. Courts, which coordinates operations across the judiciary, has issued annual Wiretap Reports. These reports detail how many wiretaps were authorized every year, breaking the numbers down by whether federal or state judges ordered them, in which states the wiretaps were conducted, what type of crime was investigated, and other data. Wiretaps allow police to gain real-time access to people’s calls, messages, and other communications. Given how invasive wiretaps can be to a person’s privacy, law enforcement have to present a high bar of evidence that a crime is being committed before a judge will authorize the use of a live tap. As such, wiretaps are generally issued in far fewer numbers than search warrants, but can still sweep up a large amount of people’s communications. Years ago, for example, one wiretap allowed a massive surveillance operation that collected millions of text messages over the course of three months. The annual wiretap reports break down the type of wiretaps authorized during the year: from audio wiretaps that can collect real-time voice from phone calls; oral taps that rely on using real-world microphones and other eavesdropping techniques; and, the electronic tapping of text messages, emails, and other messages as they pass through a provider’s network. The Administrative Office of the U.S. Courts told Democratic senator Ron Wyden this week that it will begin tracking the new “spyware/hacking” surveillance category starting in the 2028 Wiretap Report, which will be published the following year. A spokesperson for the Administrative Office of the U.S. Courts confirmed the change in an email to TechCrunch: “The Wiretap Report is compiled from individual forms submitted from throughout the country and throughout the year. Before the new data can appear in the annual report, reporting forms and procedures need to be updated to accommodate the new categories,” the spokesperson said. It’s important to note that this statistic will only reveal when authorities have used spyware to intercept communications, such as Signal and WhatsApp calls and messages, and not when they use tools to remotely hack into a phone and extract data stored inside of it, such as images, files, and their location. The first is a wiretap, and the latter is a search, which is an altogether different kind of legal process and not relevant here. Wyden, who has criticized “the unnecessary secrecy around electronic surveillance orders” and has called for this kind of data to be published since 2017, celebrated the change. “The American people remain largely in the dark about the different ways that the government is spying on them,” Wyden said in a statement to TechCrunch. “I am thankful that the federal courts agreed to collect and publish data about hacking, but Congress must go further and pass my Government Surveillance Transparency Act,” a draft bill that Wyden and others reintroduced earlier this year. Getting this kind of transparency, according to privacy experts, is a huge win. “Up until now, we have only been able to guess at the size of the problem,” said Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation and an expert on government spyware. Galperin said that once these statistics become public, it will help hold the U.S. government accountable when there are abusive uses of spyware, as it

Anthropic recently made the decision to watermark Claude’s outputs — inserting invisible code into the chatbot’s editorial text that marks it as AI-generated. Anthropic rolled out this new policy to satisfy the EU AI Act’s Transparency Code, which now requires tech companies to label content that has been AI-generated or edited in a manner identifiable to computer systems. Yet while European regulators may be happy, some AI users are decidedly not. One need look no further than Reddit to find evidence of brewing discontent, though other posters on the site are not in agreement. One of the more histrionic posts I came across was from a user named visionode, whose account is notably only three weeks old. According to visionode, the new watermarking system is a draconian conspiracy designed to victimize innocent chatbot users worldwide. Visionode’s basic argument appears to be that, while savvy Claude users may be able hide evidence of their AI usage by paraphrasing or otherwise cleaning their outputs through other AI services, the average user of Claude will be caught. “Who will get caught? You. The student who used Claude to reorganize a paragraph. The journalist who asked the AI to summarize a two-hundred-page transcript. The writer who had creative block and asked for synonyms. Those guys come out of the process with a digital tattoo on their forehead.” Far be it from me to undermine visionode’s outrage, but those are not the best examples. A journalist asking AI to summarize a two-hundred-page transcript is not going to be bothered by a watermark attached to that summary, unless they are copying and pasting the summary verbatim into their article — which is plainly unethical and shouldn’t be happening. It is equally unethical for a student who copies and pastes Claude’s output into an essay after asking it to “reorganize a paragraph.” Other Redditors were also not particularly supportive of the poster’s outrage. “Get a load of this guy,” one poster merely commented. Another asked the OP to take “a deep breath.” Visionode wasn’t the only one complaining. Another unhappy camper called the watermarks “unethical” and “disgusting” and argued that by using Claude, they had done the lion’s share of the work. In their view, the chatbot was merely a “tool” that had facilitated their arduous labor. “I gave the instructions, context, decisions, and countless refinements, claude was the tool. If Claude starts watermarking the code or anything else it generates, what exactly is it claiming credit for?” the poster asked. Again, other users dogpiled onto the critic. “It’s not claiming credit though,” one user shot back. “It’s about being able to detect AI generated outputs because of the risks AI generated outputs can cause in various situations.” “Bro couldn’t even complain about Claude without using Claude to write it,” another quipped. Some critics have steered clear of the victimhood narrative and made slightly more nuanced arguments against Anthropic’s new policy. For instance, one poster complained of a general hypocrisy in watermarking an editorial product that was, itself, generated by hoovering up other people’s work. “I think it’s a very sinister direction to take,” said the user. “I don’t use Claude to write anything but having an AI that watermarks your work is terrifyingly ironic given how many of the frontier models came by their training data.” In general, however, users have tended to support the watermarking system as a sensible way to track material that was generated by algorithm. “There is literally no good argument for why this isn’t a good idea,” a user on another thread said. “The only reason you wouldn’t want this is to lie to people.” When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Lucas is a senior writer at TechCrunch, where he covers artificial intelligence, consumer tech, and startups. He previously covered AI an

For more than a decade, the cybersecurity industry has been assigning names to different hacking groups. Some of them, like Fancy Bear, have crossed over into the mainstream because of their prominent hacks and memorable names. Others are only known within the cybersecurity industry. Oftentimes, even industry insiders can’t keep track. In part, that’s because every company names hacking groups differently. That’s why there are resources like this one, which attempt to be a one-stop shop where cybersecurity professionals, government officials, policymakers, journalists, and the wider public can make sense of who is who. Last month, Google became the latest company to revamp its naming system for hacking groups. Gone are the days APT1, APT41 or APT whatever number, which was the system adopted by Mandiant, once an independent security firm that’s now part of Google. Mandiant was the first to adopt a naming scheme. From now on, Google’s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. According to Shane Huntley, the chief technology officer of Google Threat Intelligence Group, the company’s in-house hacker hunting team, the revamp was necessary to bring clarity to security researchers both inside the company and externally. In the early 2010s, when companies started publishing reports on cyberattacks and naming the hackers behind them, Huntley told TechCrunch that, “we were not expecting to have as many threat groups as we do today.” It had become hard to keep track of everyone. Google now tracks more than 5,000 “activity clusters” in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said that there are very few developed nations that don’t have their own cyber capabilities and hacking groups. But what is the point of naming hacking groups? It’s not just an academic exercise, Huntley explained. The goal is to have a baseline understanding of who is attacking who, and how they are attacking them. That way organizations can recognize threats more quickly, prepare against them, ideally stop them, or at least investigate incidents more promptly. All that, he said, it’s possible only if you name the hackers and track them consistently. “If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,” said Huntley. Knowing how the North Korean government hackers known as the Lazarus Group behaves, what their goals usually are, and who they work for, gives defenders a starting point in dealing with these hackers. Tracking state-sponsored hackers, while challenging, is easier than tracking cybercriminal groups and hackers-for-hire, Huntley explained. The government hackers tend to have more consistent targets and activities, while cybercriminal groups have members that come and go, sometimes splinter, and otherwise are more amorphous. Hacker-for-hire groups and spyware makers tend to have a lot of customers in different parts of the world, making them slightly harder to track. A common criticism whenever a new naming system gets announced is: Why don’t all companies and organizations just use the same codenames? While that seems like an easy question to answer, the reality is that every company has a slightly different view of every group, based on their own sets of data and telemetry. Huntely said this is an inescapable reality that can’t be avoided just by sharing more information among companies and groups of researchers. “No one has perfect visibility,” he said. “We are building our model and our best understanding, but we will never know everything about what

Over the last few decades, several mysterious hackers have captured the public’s imagination, but none quite like Phineas Fisher. A decade after their most famous hack, Phineas remains, by most accounts, the most prolific and public hacker never to have been caught. As part of our series on the biggest cybersecurity mysteries of all time, we’re delving into the enigma of Phineas, the hacktivist who hacked controversial spyware makers FinFisher and Hacking Team. The latter, an Italian startup, was among the first to turn government spyware into a viable global business, paving the way for spyware makers such as the Israeli NSO Group. Phineas’ hack against Hacking Team eventually led to the startup’s demise years later. Apart from Anonymous, an amorphous amalgam of hacktivists with a mixed track record of mostly stunt hacks designed to gather publicity rather than have real impact, Phineas is perhaps the most well-known hacktivist in history. Their story is made of impressive hacks and endless unanswered questions. Who is Phineas Fisher? Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades. The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There’s even a song about them. Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data including mobile spyware, product manuals, and a price list. The damage was limited, and FinFisher carried on. Phineas published a post-mortem that doubled as a leftist manifesto, then vanished. A year later, they came back with a bang, hacking Hacking Team, another spyware maker. They took practically everything: more than 400 gigabytes including source code, tens of thousands of internal emails, confidential contracts, and customer lists. The leak allowed journalists to reveal scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was forced to sell his company for one euro. For some former employees, Phineas’ hack was the beginning of the end. Phineas went on to hack the union of the Mossos d’Esquadra, which is the police force of Catalonia, publishing a post-mortem and a 39-minute tutorial video — consistent with their stated anti-police ideals. Their next victim was the ruling party of Turkey’s authoritarian president Recep Tayyip Erdoğan, a hack motivated by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was fighting against. Phineas’ last known victim was Cayman National Bank’s branch in the Isle of Man, a self-governing island between England and Ireland. The hack hinted at a different side of Phineas. “I look for illegal ways to make money in order to free my time so I can do something useful with it. Once I had that figured out, I started scaling it up and making more money than I need and giving the extra away,” Phineas said in an interview with activist Freddy Martinez. (Phineas donated at least $10,000 in Bitcoin to Rojava.) Phineas kept the hack — which happened in 2016 — quiet for three years later before announcing the “Hacktivist Bug Bounty Program,” an initiative to reward hacktivists who expose companies’ illegal and unethical activities. When Cayman National Bank confirmed the hack, it claimed it “was amongst a number of banks targeted.” Phineas confirmed they had been hacking several banks for years. That was their last public appearance. Their Twitter and Reddit accounts have long since been

The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war. In an advisory updated Wednesday, the FBI, the NSA, the Department of Energy, and CISA said Iranian hackers were targeting programmable logic controllers on internet-connected operational networks, allowing them to manipulate data on their displays, causing outages and disruption. The Iranian hackers were initially discovered earlier this year to be targeting controllers made by Rockwell, but the advisory has now expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens. The agencies warn that “potentially all internet exposed” industrial control systems may be affected, and urged critical infrastructure owners to take action. Per the advisory, the Iranian-backed hackers were “conducting this activity to cause disruptive effects within the United States,” likely in response to the ongoing war between Iran, and the U.S. and Israel. According to the FBI, the hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disabled processes that handled critical shutdowns and alarms. The feds said this allowed “systems to enter unsafe conditions without notifying operators of the anomalies.” This is the latest in a series of cyberattacks launched by Iranian government hackers and their proxies across the region since the start of the war in February. The hacks have ranged from the country’s typical espionage and hack-and-leak operations, such as leaking the contents of the FBI director Kash Patel’s personal email account, to more atypical destructive hacks that have caused large-scale damage or disruption. Among the more notable incidents was a hack on the U.S. medical tech giant Stryker, which allowed the Iranian hacking group “Handala” to remotely wipe tens of thousands of employee devices. Handala also took credit for a data breach affecting California water provider Cal Water in June, and claimed it could have disrupted the water supply (without providing evidence). The water provider said that it saw no evidence of unauthorized access to its operational networks, which control the water supplies. When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com. View Bio

It turns out that even San Francisco Mayor Daniel Lurie, who once declared that the city should be a testbed for emerging tech, has his limits. Especially when that emerging tech creates a massive hours-long traffic jam that leaves thousands at a standstill. Mayor Lurie has asked state regulators to bolster rules for autonomous vehicles nearly two weeks after Waymo robotaxis became immobile in heavy July 4 traffic, ran out of power, and blocked key streets, further compounding the gridlock. The traffic jam, which trapped municipal shuttles, became a citywide problem that affected thousands of people. In his letter to the state Department of Transportation, which was viewed by TechCrunch, Lurie pointed to two events — a widespread power outage in December and the Golden Gate Bridge fireworks show on July 4 that attracted 100,000 spectators — both of which led to dozens of stranded Waymo vehicles and paralyzed traffic. The San Francisco Chronicle first reported on the letter. The events, he said in the letter, “demonstrated that California’s current regulatory framework does not adequately address how autonomous vehicles operate during major incidents, planned or not. California’s challenge now is not just whether autonomous vehicles can operate safely under normal conditions, but also whether they can perform reliably during extraordinary ones.” Lurie said autonomous vehicle manufacturers should be able to demonstrate four “core operational capabilities” and asked the California Department of Transportation to establish statewide standards to prevent future problems like the July 4 gridlock incident. Under Lurie’s vision, companies would be required to immediately remove or relocate robotaxis from active travel lanes to keep people moving and be required to be able to adapt in real time, adjusting their routes, service area, and pick-up and drop-off locations. Companies would also have to share real-time operations data with local agencies, including service disruptions, the locations of immobile robotaxis, and recovery efforts as well as demonstrate through testing that they can handle large influxes of people and traffic. TechCrunch has reached out to Waymo for comment. The article will be updated once the company responds. Any company that wants to operate a robotaxi service in California has to successfully navigate two testing and deployment permit processes, one administered by the state’s Department of Motor Vehicles and the other by the Public Utilities Commission. California’s existing regulatory framework is stricter than that of other states like Texas and Arizona, but that hasn’t dissuaded companies from trying to operate there. San Francisco and the wider area that stretches south into Silicon Valley have long been a testbed for autonomous vehicle technology. Six companies, including Nuro, Waymo, and Zoox, hold driverless testing permits, which allow the vehicles to drive without a human safety operator behind the wheel. But the area has also become the launch point for commercial services, which requires other permits from the DMV and CPUC. Waymo is the largest, with an estimated 1,000 robotaxis operating in the Bay Area today. But there are plenty of others either testing or poised to launch commercial operations, including Amazon-owned Zoox as well as a premium robotaxi service that will be operated by Uber. Tesla has a branded robotaxi service but it doesn’t use driverless vehicles, nor does it have the permits to do so. Instead, Tesla has a charter transportation permit, which allows its own drivers to pick up and drop off riders throughout San Francisco in vehicles equipped with its advanced driver assistance system rather than fully autonomous software. Waymo’s scale has made it the focal point for regulators in San Francisco, and beyond. The company now operates in 11 cities and has said it completes more than 500,000 paid rides every week. In San Francisco, Lurie noted that Waymo had agreed to re

Vinton Cerf will step down from his role as Google’s chief internet evangelist next week, marking the conclusion of one of the most influential careers in technology history. While speaking at the Open Frontier conference hosted by the Laude Institute, Cerf was recognized by Dave Patterson, the UC Berkeley professor best known for co-developing RISC processor architecture. “Vint…has been at Google more than 20 years, and he is retiring a week from today, and so I think we ought to give him a round of applause for a relatively good career,” Patterson said, to cheers from the room. Google did not respond to a request for comment by publication time. Cerf, 83, and collaborator Robert Kahn are credited as the architects of the networking protocols that became the internet we know it today. His work developing and popularizing TCP/IP — the basic set of rules that lets different computer networks talk to each other — beginning in the 1970s has been recognized with numerous honorary degrees, the Presidential Medal of Freedom, and a Turing Award, among other honors. Since 2005, Cerf has served as a vice president and chief internet evangelist at Google. (At this point, we can safely say the internet is fully evangelized, for good or ill.) Cerf was speaking on a panel alongside other computer scientists known for their work on durable open source projects, including Patterson; François Chollet, creator of the Keras deep-learning library and co-founder of Ndea; John Ousterhout, the Stanford computer scientist behind the Tcl programming language, who also co-founded Electric Cloud; and Matei Zaharia, who is Databricks’ co-founder and chief technologist. They offered advice about what it takes to build open source systems that survive — advice that’s increasingly relevant as founders bet on open infrastructure for the next wave of AI products. Much of the conference’s discussion focused on the problems with the centralization of advanced models in a handful of well-resourced labs, in contrast to the decentralized world of the open internet that made Cerf’s own protocols so durable. However, Cerf predicted that the rise of AI agents — software that can act autonomously and coordinate with other software — would push tech companies back towards standardized protocols. “The agentic model of AI, with multiple agents from multiple sources interacting with each other, is going to force composability, and a requirement for interoperability and standardization,” Cerf said. If he’s right, the companies that define those interoperability standards early could end up with outsized influence over how the agentic economy actually works — a dynamic not unlike the early internet protocol wars. While other panelists speculated that natural language communication between LLM agents would be sufficient, Cerf predicted formal standards would be required. “I don’t think English is going to be the best choice. There’s a flexibility in it, but there’s ambiguity, and I think precision for interagent interaction is going to be very, very important. An agent really needs to be sure the other agent understands what it is that they just agreed to do together,” Cerf said. “Remember the old telephone game where you wish you’d whispered in somebody’s ear and then by the time it got to 10 people away the message was totally different? Imagine a bunch of agents talking to each other in natural language, you know, that’s kind of terrifying.” In a more light-hearted moment, Patterson recalled meeting Cerf, known for his wardrobe of three-piece suits, as a grad student in the 1970s. “He’s always been the best dressed computer scientist I’ve ever met,” Patterson said. “My memory of Vint is that he came as a grad student with a shirt and tie in the 70s.” “It absolutely is true,” Cerf said. “I even had a vest, and for some reason I always wanted to stick out, and instead of having long hair, and something in my nose, I thought just dressing differently was one

Proton, the privacy-focused productivity app company, released a public AI chatbot, Lumo, last year. On Tuesday, the chatbot received an upgrade. Lumo 2.0 gives the chatbot a variety of newfound powers including image recognition and image generation capabilities. Users can now upload pictures into Lumo, then use the chatbot to analyze or edit them. Similar to other LLMs, Lumo can also generate imagery based on a user’s prompt. 2.0 also expands Lumo’s capabilities for Projects — the widget that allows users to upload documents and conduct work via Proton’s other products like email, cloud storage. Projects now come with user-controlled persistent memory, which is a function that allows Lumo to recall a user’s preferences across various conversational sessions. Additionally, the company says Lumo’s update makes it significantly more powerful than its previous version. The 2.0 version responds to most queries up to 76 percent faster than its previous iteration, the company says. The chatbot also comes with a new “thinking mode” for more complex problems or questions. “Lumo 2.0 has been re-engineered from the ground up and the introduction of thinking mode gives it powerful new capabilities,” said Andy Yen, Founder and CEO at Proton. “Lumo 2.0 demonstrates that users no longer need to choose between powerful AI capabilities and meaningful privacy protections.” The public version of Lumo appears roughly equivalent to other major chatbots in terms of usefulness. It answers questions in a similar format as Gemini and ChatGPT, with approximately the same level of detail and context. Yet, Proton distinguishes Lumo from other chatbot providers with its privacy protections. It uses what it calls zero-access encryption architecture, which encrypts users data in transit and at rest, only allowing access to the user. The company also claims that no server-side logging of sessions is retained, so nobody at Proton can see the contents of conversations. Proton also promises to never use customer data for AI training or share it with third-parties. Lumo 2.0 is available immediately. In addition to the free public version, Proton offers paid tiers (Plus and Professional) that give those users significantly more access and resources. When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Lucas is a senior writer at TechCrunch, where he covers artificial intelligence, consumer tech, and startups. He previously covered AI and cybersecurity at Gizmodo. You can contact Lucas by emailing lucas.ropek@techcrunch.com. View Bio

Pinterest on Wednesday announced a new experimental app called “Ask Pinterest” that will allow the company to explore a more conversational approach to shopping and product discovery that could eventually find its way to the main Pinterest app. It also introduced other AI initiatives, including Pinterest Model Context Protocol (MCP), designed for advertisers running campaigns on Pinterest’s platform, and other AI ad tools. The news comes just ahead of the adtech industry’s annual gathering at Cannes Lions, which is this year mainly focused on how AI can serve the needs of advertisers and marketers. The “Ask Pinterest” online application gives the company another way to utilize its “Taste Graph” — its internal data mapping people to their interests and aesthetics. It will initially be available in limited access, the company said. The AI-powered experience is designed to expand the visual discovery experience Pinterest is known for beyond the main app to a conversational, chatbot-like interface where consumers can ask questions using natural language to get more personalized recommendations and inspiration. It also arrives as AI chatbots are increasingly competing with traditional search engines for consumers’ attention. Google has already put AI to work to help online shoppers find what they need, track prices, and check out. ChatGPT also experimented with agentic shopping, as have Meta, Shopify, and others. Rather than turning itself into a source of product recommendations that other AI services could leverage through licensing deals, Pinterest has largely focused on using its own data to train AI models and power its AI products. Image Credits:Pinterest Plus, by making Ask Pinterest a standalone app, the company has a way to experiment with the technology without disrupting the main Pinterest experience. The company explains that Ask Pinterest could work for more complex or multi-step queries that wouldn’t fit a traditional Pinterest search. For instance, you could use the app to ask for help planning a dinner party or furnishing a room over time. The idea, says Pinterest, is to test and explore how AI could better support people’s shopping experiences while retaining the user’s context across sessions. Ask Pinterest can also leverage users’ own saved Pins and Boards to personalize its answers. In time, these results will help Pinterest when building more AI-powered experiences for the company’s flagship app, the company believes. Image Credits:Pinterest Pinterest’s new app was announced alongside the updates aimed at marketers, including the introduction of an AI assistant, still in beta, in its Ads Manager in the U.S. A new AI model, Performance+ creative, was also introduced globally to help advertisers pick between different ad creatives to find the one that’s likely to perform best each time the ad is shown. And the MCP infrastructure layer that Pinterest announced will allow advertisers to manage and monitor their campaigns using other third-party agentic tools in a standardized way. In an announcement sharing the news, Pinterest’s Chief Business Officer, Lee Brown, gestured towards the changing nature of web search, remarking that, “the future of discovery won’t be driven by keywords alone. It will be shaped by context, taste, and trusted recommendations” — an area where Pinterest feels it has a “unique advantage,” Brown said. When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software. You can contact or verify outreach from Sarah by emailing sarahp@techcrunch.com or via encrypted message at sarahperez.01 on Signal. View Bio
Discussion (0)