AI agents are capable of drastically reducing the cost and increasing the scale of attacks on cryptocurrency owners, participants at the Wyoming Blockchain Symposium stated. In their opinion, automation will allow malicious actors to simultaneously search for vulnerabilities in the wallets, passwords, and networks of a large number of potential victims.
Ryan Kirkly, co-founder and CEO of Global Settlement Network, believes the industry too often views autonomous agents only as a useful tool and underestimates the possibility of their use by attackers.
"We act as if agents are always good. I think that's a fatal mistake in almost everything related to such systems today," he said.
According to TRM Labs, in the first half of 2026 alone, the crypto industry faced 207 hacks – the highest number for any six-month period in the company's statistics. The total damage amounted to $972 million.
According to Kirkly, it was previously economically unprofitable for a malicious actor to spend a lot of time and resources on attacking an individual with a relatively small crypto portfolio. AI agents change this economics: one autonomous system can potentially be deployed against a large number of targets simultaneously.
The expert suggested that in such a scenario, even current major attacks on crypto protocols might look small compared to the aggregate damage from mass automated campaigns.
TRM's data shows that attacks are already becoming more widespread. From January to June, their number doubled compared to 83 cases in the same period in 2025. At the same time, infrastructure and operational compromises – including the theft of private keys and seed phrases – accounted for only about 15% of incidents but resulted in roughly 76% of all losses.
Easier and Faster
Bill Laboon, Vice President of Technical Operations at the Web3 Foundation, agreed that the advantages of autonomous systems simultaneously simplify the activities of malicious actors.
"This means there's less friction for the bad guys too. For the good, the bad, and the neutral," he noted.
The main advantage of AI agents lies in their ability to independently perform sequences of actions: searching for information, accessing external services, working with code, and using available tools without constant human involvement.
The same properties allow them to be used for automated target and vulnerability discovery.
Practical capabilities of such systems are already being used by defenders. In July, the Ethereum Foundation employed AI agents to analyze critical components of the blockchain. The systems studied code, searched for potential vulnerabilities, and prepared materials for proof-of-concept.
The foundation, however, emphasized the need for manual verification of results: a significant portion of the candidates found by the agents turned out to be false positives, duplicates, or issues outside the scope of the research.
How Much Power to Give an Agent
Separately, discussion participants addressed the risk of connecting autonomous systems directly to a user's financial tools.
"The idea of giving one agent all this power – access to my credit card data, security information, Social Security, all personal data, and various accounts – seems frightening without clear limitations," said Fahmi Syed, President of the Midnight Foundation.
Kirkly considers permission management a solvable task. A more serious threat, he called the compromise of the agent itself or the environment in which it operates.
"Aren't we creating a new attack vector where an agent can be hijacked and the entire wallet emptied?" he wondered.
A similar problem becomes more relevant as wallets and crypto services emerge that allow AI to independently manage assets. On August 6, MetaMask opened general access to Agent Wallet. A user can set spending limits, allowed networks, addresses, and protocols for the agent, after which the system independently performs operations within the established limits.
MetaMask also warned about the risk of "prompt injections." If an agent simultaneously analyzes data from external sources and is capable of initiating financial operations, a hidden malicious instruction could potentially lead to an irreversible on-chain transaction.
To mitigate the risk, the wallet separates the model's decision-making from policy verification and transaction signing.
Other Risks
Laboon pointed to another potential problem – a false sense of privacy. Even if a blockchain or application hides the content of transactions, accompanying metadata may allow algorithms to correlate individual pieces of information and reconstruct connections between users.
"That's what really worries me: metadata leakage. People will think they are protected because they are using a private network," said the Web3 Foundation representative.
In addition to security, panel participants named a lack of trust as one of the main barriers to the widespread adoption of AI agents. Laboon reminded that modern language models are still capable of generating erroneous information.
"My LLMs still hallucinate sometimes. I wouldn't want to hand my retirement account over to them," he noted.
Richard Shorten, founder of Silvermine Capital Advisors, believes that the development of agent technologies outpaces the speed at which users and companies can comprehend the consequences of their implementation. According to him, the task is to turn technical capabilities into systems that people are willing to grant control over at least parts of their business or daily life.
Who is Responsible for an Agent's Error
Another unresolved issue concerns legal liability for autonomous actions. Kirkly raised the question of who should be held accountable if an agent independently violates the law, transfers funds to the wrong recipient, or performs an operation that cannot be reversed.
"If your agent does something illegal or spends money it shouldn't have, how do you get it back? Who makes the final decision? The question is who ultimately bears the responsibility," he said.
The problem is especially noticeable in blockchains, where a completed transaction in most cases cannot simply be canceled.
Five Childhood Diseases of AI
Previously, Anthropic discovered problems with trust, lying, and collusion in multi-agent AI.
Recall that in August, the ForkLog editorial team examined the concept of the "reverse centaur," described by Cory Doctorow, and found out who benefits from such automation.





