Author: Sean Stein Smith, Forbes
Compiled by: AididiaoJP, Foresight News
In recent years, the discussion around AI risks has evolved at a dizzying pace. The challenges facing enterprises today are no longer minor issues like chatbots occasionally spouting nonsense, outputting biased views, or employees accidentally pasting sensitive information into public tools. The real qualitative shift lies in this: AI agents have now acquired the ability to take direct action—they can call external systems, write their own code, and independently advance a complex, multi-step series of tasks with little to no human oversight.
This transformation poses an extremely severe challenge to financial markets, especially the crypto market. Crypto assets trade 24/7, smart contracts execute automatically, and transactions on the blockchain, once confirmed, are often irreversible. Once these AI agents gain access to wallets, exchanges, DeFi protocols, or payment systems, even a minor permission loophole can directly escalate into an irrecoverable financial loss. Therefore, agent-based AI risk is no longer just an IT department concern; it has simultaneously become a core issue of corporate governance and crypto asset control.
Crypto Mechanisms Magnify the Lethality of AI Autonomous Actions
A recent incident disclosed by the UK's AI Safety Institute brings this dangerous 'autonomy' into sharp focus. During a cybersecurity assessment test, an AI agent took persistent and entirely unauthorized actions against real individuals and organizations. Although ultimately stopped in time, it was enough to prove that AI agents are fully capable of combining capabilities like planning decisions, tool calling, persistent operation, and external access in unexpected ways to carry out real-world attacks.
When crypto assets are involved, the financial risk grows exponentially. An agent with access to private keys or a connected wallet could transfer assets, sign malicious contracts, misappropriate collateral, or even interact arbitrarily with decentralized protocols. This is completely different from traditional bank transfers—there's no customer service to help you freeze an account urgently, no bank to stop a transaction, and no 'reversal' process. Once funds are transferred out, they are almost as good as gone forever.
Even more critically, the crypto market never sleeps. AI agents can operate in the middle of the night, on weekends, or while all employees are asleep. Automated trading or liquidation programs could, within mere minutes, snowball a small, initially manageable error into a catastrophic loss. Therefore, when enterprises assess AI agent risk, the focus should not be on how smart the model is, but rather on which systems and assets it can access. An agent with average capabilities but wide-open permissions to directly operate a wallet is far more dangerous than a more capable model securely locked inside a sandbox. Permission design is becoming the critical line of survival, even more crucial than model selection.
Internal Controls Must Extend into Every Crack of Wallets and Smart Contracts
Many enterprises have already established a series of traditional internal control measures like separation of duties, approval limits, access reviews, and change management. The problem is that these principles must be implemented without compromise for every AI agent that interacts with crypto systems.
No agent should possess an 'all-in-one' capability—for instance, simultaneously creating a wallet, modifying address whitelists, and initiating transfers, all without requiring human intervention. High-risk transactions must mandate human approval, and the approver must receive clear, complete information: recipient address, asset type, amount, network, gas fees, and exactly what the transaction is intended to do. Vague, automatically popping reminders like 'Please confirm system operation' do not constitute effective controls; they only create a false sense of security.
Private keys and signing permissions require special protection. Agents must never be allowed to freely read seed phrases or signing credentials. Designs like multi-signature mechanisms, hardware security modules, per-transaction limits, and transaction delays can effectively reduce the risk of 'one exploited vulnerability leading to an instantly emptied wallet.' Before interacting with smart contracts, simulation execution and strict validation are essential, especially when dealing with unlimited token approvals or contracts from unknown sources—extra caution is warranted.
Enterprises must also establish comprehensive operational logs—what the agent accessed, what instructions it received, what transactions it proposed, which ones ultimately succeeded on-chain, and whether a human was consistently in the loop for these operations. These records are indispensable for post-incident accountability, security audits, asset protection, and even financial disclosure. Without logs, assigning responsibility becomes impossible when something goes wrong.
AI + Crypto Incidents Require Industry-Shared Lessons
The Linux Foundation and the Open Security AI Alliance have already launched the "Shared AI Findings Exchange" (SAFE) mechanism, aiming to help organizations learn from real AI security incidents and close calls on a confidential basis. Crypto companies, banks, custodians, exchanges, and audit firms should actively participate in this type of information sharing.
The crypto industry long ago understood the value of meticulously analyzing hacker attacks, cross-chain bridge collapses, key leaks, and smart contract vulnerabilities. Agent-based AI adds a new dimension to this old problem—an incident may simultaneously involve the model itself, prompt design, tool integration, access policies, and the final on-chain transaction. Therefore, truly useful incident reports must clearly explain all these layers, not vaguely dismiss it as 'the AI had a problem.'
Boards of directors should start asking clear questions now: Has agent-based AI been incorporated into wallet governance, cybersecurity incident response plans, and upgrade approval processes? Auditors must also consider whether unauthorized agent operations could lead to direct asset loss, misstatement of balances, hidden liabilities, or even material weaknesses in internal control systems. Finance teams need to think ahead: If a malicious or failed on-chain transaction occurs, how will it be identified, valued, and truthfully disclosed in financial statements?
Of course, AI agents are not solely about risk. In the future, they could significantly enhance the efficiency of crypto compliance, automated reconciliation, fraud detection, and fund management. These benefits are real and promising. But the prerequisite is that autonomous capabilities must be paired with sufficiently robust control mechanisms. Otherwise, a small oversight in the code can, in the blink of an eye, turn into an on-chain transfer that can never be recovered.
In the world of crypto, responsibility must be designed, embedded, and tested *before* agents are truly granted the power to act. Whether you are a believer in crypto or an advocate for AI, this point should be squarely faced—because once control is lost, the outcome is often permanent.








