Why Is AI Agent Shopping Hard to Popularize?

Foresight NewsXuất bản vào 2026-07-20Cập nhật gần nhất vào 2026-07-20

Tóm tắt

The article argues that the popular narrative of "AI agent shopping" – equipping AI with a wallet to autonomously handle purchases – is fundamentally flawed and oversimplifies the complexity of shopping. It deconstructs shopping into two core actions: **information retrieval** (standardized, easily automated) and **value judgment** (deeply subjective and human-centric). The narrative mistakenly assumes AI can fully handle both. Value judgment itself has two layers: **evaluation** (assessing options against criteria) and **demand definition** (setting the criteria, weights, and values). The latter is inherently human and dynamic, as preferences are not fixed but constructed during the decision-making process ("constructive preferences"). The real dividing line for automation is not product standardization, but whether the **act of choosing** itself holds experiential value. For mundane purchases (e.g., printer paper), full AI delegation works. For experiential goods (e.g., wine, furniture), the joy of selection is core to consumption, so AI should act as an assistant that narrows options, leaving the final choice to humans. The "AI wallet" concept confuses three separate elements: decision-making, execution, and fund custody. Current payment industry solutions (e.g., from Stripe, Mastercard, Google, Visa) show that limited, scoped payment authorization tokens are sufficient for most consumer scenarios, not full fund custody. The true use case for autonomous AI wallets is in...


Written by: Anderl

Compiled by: Chopper, Foresight News


Currently, there is a narrative circulating in the AI and crypto industries: equip an AI agent with a wallet and let it take full charge of shopping for people, which is the most core landing scenario for AI. This argument sounds simple and perfect, almost like the future, but its internal logic cannot withstand scrutiny. This viewpoint confuses the difficult and simple aspects of shopping and places the simplest payment link at the core position.


Let's first put aside payment and return to the shopping behavior itself.


The Two Core Behaviors of Shopping


Shopping is essentially two types of actions that are now bound together: information retrieval and value judgment. Retrieval (collecting, filtering, comparing, and preliminary sorting) has standardized attributes and can almost be entirely handled by machine agents; while value judgment (whether this product is good, suitable for me, or if the merchant is trustworthy) is a link deeply bound to human subjective emotions.


Data has already proven that information retrieval is rapidly shifting towards AI. Adobe Analytics data shows that from July 2024 to July 2025, visits to US retail websites driven by generative AI surged by approximately 4700%. However, the "AI wallet" narrative defaults to the assumption that intelligent agents can simultaneously take on both retrieval and value judgment, which is the key point where the entire logic equivocates concepts. Retrieval can be completely handed over to machines, while value judgment can only be partially delegated under specific conditions, and in most scenarios, it cannot be entrusted at all.


Value Judgment is Further Divided into Two Layers


More crucially, value judgment itself is not a single dimension but is divided into two parts. One part is evaluation, which is testing various options based on a utility function. The other part is demand definition, which is first setting the utility function: which dimensions are important, what their weights are, which values are binding, and the ultimate meaning of "good."


Demand definition is not completed just once at the beginning; it runs through the entire shopping process. The product compliance standards are decided by you; whether a broken zipper directly disqualifies a product is determined by your judgment criteria; choosing which merchant depends on your valued orientation. Each layer of screening follows the logic of "human subjective standards × AI machine evaluation." Automation can only replace the evaluation part; the sovereignty of defining demands always lies in human hands.


Many people mistakenly believe that humans only need to write a standard list once to completely let go, which seriously underestimates the logic of human decision-making. Abundant research in the field of decision-making confirms that human preferences are not fixed. Psychologist Paul Slovic proposed the constructive preference theory: we do not have a ready-made, fixed set of preferences waiting to be retrieved from within; preferences are gradually formed during the process of making choices. The "preference reversal" experiment confirms this: two equivalent research methods, choice and pricing, yield completely different product rankings, violating the basic axioms of rational choice.


Ariely, Loewenstein, and Prelec proposed the "coherent arbitrariness" theory in 2003: even random numbers with no relevance, like the last few digits of a social security number, can anchor people's psychological bids for ordinary commodities; and this anchoring effect does not disappear with consumption experience or market transactions. So-called "stable preferences" are merely artificially constructed illusions of order.


Therefore, human-machine interaction cannot be a one-time completion of a standard list; it requires continuous iterative communication. The AI agent raises targeted questions at each screening node: "You previously valued durability; at what price premium is durability no longer cost-effective for you?", and then humans define this boundary in real-time.


The Real Dividing Line: Is Procurement a Chore or Enjoyment Itself?


The industry habitually uses "standardized goods / personalized goods" to divide scenarios, but the divergence does not lie in whether standards can be quantified. The real dividing line is: whether the act of making a choice itself has experiential value.


For items like printer paper, batteries, or commodities that need regular replenishment, the selection process holds no experiential value. No one wants to spend energy comparing two almost identical ink cartridges. These types of goods are naturally suitable to be completely handled by AI agents; automatic machine repurchases do not lose any experience.


For enjoyment-based consumption, the situation is exactly the opposite. Wine, furniture, coats, books—the act of selecting is itself part of the pleasure of consumption. If the judgment power is handed over to a machine, although it saves time costs, it directly deprives the core fun of consumption. Even if the AI provides free Q&A throughout, people are unwilling to delegate it completely.


For enjoyment-type goods, AI agents should not make decisions entirely but should switch to the role of information gatherers: completing retrieval, preliminary screening, parameter matching, merchant qualification verification, extracting common product flaws from massive reviews, reducing 200 options to 5, and then leaving the final choice to humans.


The Triple Dilemma: AI Inquiry, Historical Inference, Autonomous Decision


Some might say: can't the AI just ask for my judgment criteria directly? This approach is precisely the inefficient mode that ordinary people would find annoying in daily life. More fatally, repeatedly asking about standards distorts people's final choices.


Wilson and Schooler conducted a jam evaluation experiment in 1991: the group that was required in advance to sort out reasons for their preferences ultimately gave rankings that deviated more from professional tasting standards; subsequent experiments proved that forcing people to list reasons for choices item by item led them to choose decorative paintings with lower satisfaction afterwards. Language can only describe easily expressed surface features, unable to capture true inner preferences; sensations like taste and aesthetics can only be perceived, difficult to define with words.


Thus, a triple dilemma arises where all three cannot be satisfied simultaneously:


  • Active AI Inquiry: Aligns with current true preferences, but interaction friction is extremely high, even distorting choices;
  • Inference Based on Historical Behavior: Smooth operation, but confines to past preferences, stifles new consumption exploration;
  • Fully Autonomous Human Judgment: Completely retains choice power, but consumes vast time and energy.


A fourth compromise solution can avoid the above drawbacks: recognition-based interaction, rather than item-by-item inquiry. The AI directly shows 3 options, and humans only need to pick directly. This method is both hassle-free and accurate because it doesn't require abstractly naming standards you often cannot name.


The classic choice overload experiment can corroborate this. Iyengar and Lepper conducted a jam tasting stall experiment in 2000; the purchase conversion rate was much higher when 6 types of jam were displayed compared to 24 types. However, this theory is controversial, and subsequent multiple analytical experiments overturned this conclusion. Scheibehenne et al. summarized numerous experiments in 2010 and found no universal choice overload effect overall; Chernev, Böckenholt, and Goodman's analysis covering 99 studies in 2015 showed that the overload effect only appears when product complexity is high, decision difficulty is great, and personal preferences are vague. The original authors later reviewed that consumers lacked sufficient time to sort out their own preferences when facing 24 products. True autonomy lies between "the agent applies my standards" and "the agent fabricates standards based on my historical records."


Returning to "AI Wallet": Payment is Only the Most Minor Link


Clarifying the above logic reveals the flaws in the "equip AI with a wallet" narrative. This argument confuses three completely independent things: decision-making entity, execution entity, and fund-holding entity. "Equipping AI with a wallet" only solves the fund custody problem; it only makes sense when the AI also possesses decision-making power.


There are three scenarios. First, the person decides and pays themselves. In this case, the agent does not pay but acts as a scout. Second, the person makes the decision and delegates the execution to the agent ("Yes, buy that one"). Here, the agent is responsible for checkout but does not need to hold funds; it only requires a limited, one-time, revocable authorization for this specific approved purchase. Only in the third scenario, when the agent autonomously decides and pays without human presence for checkout, does the wallet itself bear the payment responsibility.


Interestingly, by 2025, the global payment industry had already implemented layered authorization solutions, clearly distinguishing "authorization" from "fund custody":


  • OpenAI partnered with Stripe to launch a smart agent commercial agreement, generating shared payment tokens bound to a single merchant, for a fixed amount, and one-time use within a time limit; the AI cannot obtain the full bank card number;
  • Mastercard released Agent Pay in April 2025, generating dedicated tokens limited to specific agents, designated merchants, and bound to user authorization rules;
  • Google launched the AP2 smart payment protocol in September 2025, clearly splitting "user demand authorization credentials" and "AI procurement list credentials," both being verifiable cryptographic credentials, perfectly corresponding to the layered logic of "demand definition / machine evaluation" mentioned earlier;
  • Visa launched the Trusted Agent Protocol in October 2025, following the same logic as the above solutions.


Leading payment institutions have unanimously proven the core point of this article: there is no need to hand funds over to AI; granting limited operational permissions is sufficient.


So, where is the true applicable scenario for AI-independent wallet custody? Consumer retail scenarios hardly need AI wallet custody; the real landing space for this solution lies in standardized bulk commodities and automated machine-to-machine settlement. Coinbase and Cloudflare jointly launched the x402 protocol, filling the gap of traditional card payment channels: supporting automated agent-to-agent payments without human intervention, 7×24 hours, billed per API call, with transaction volume exceeding 100 million within months of launch. Mastercard simultaneously launched Agent Pay for machines, serving high-frequency, low-latency small-amount machine settlement. This is the underlying infrastructure of the machine economy, not for personal shopping.


This narrative itself is not wrong, but its importance is completely reversed: AI-independent wallet custody only holds significant value in scenarios where goods are highly homogeneous and individual transaction amounts are relatively low.


Where Should the Wallet Really Be Placed


This also explains the shift in focus in the crypto sector over the past two years: no longer primarily pushing the narrative of consumption liberation for individuals, but instead deeply cultivating institutional underlying infrastructure — stablecoin clearing, asset tokenization, enterprise-level services. This is not abandoning the AI shopping track but returning to the field truly suited for the wallet custody model: the enterprise side. Corporate procurement departments themselves are the institutionalized embodiment of "pure chore procurement." The procurement process strips away subjective aesthetics and personal feelings, relying entirely on specifications, price, fulfillment, and contract terms for decision-making, essentially an artificial version of intelligent agent procurement. The AI wallet merely automates the already mature enterprise process; there is no behavioral model disruption.


Today, many companies outsource office supplies and low-value consumables procurement. The core competitiveness of platforms like Mercateo and Amazon Business is not low prices but reducing process costs: unified procurement catalogs, consolidated billing. Companies are willing to accept slight premiums on individual items in exchange for a significant reduction in procurement manpower costs; the process cost for low-value consumables often exceeds the value of the goods themselves. AI agents can reduce order placement manpower costs to near zero while retrieving from a vast, dispersed pool of suppliers; procurement platforms retain only compliance verification functions: qualified supplier vetting, unified reconciliation, anti-counterfeiting checks, and verification is precisely the real bottleneck of the entire process.


Therefore, the landing strategy cannot be simply summarized as "wallet serves enterprises, not individuals." The precise expression should be: tools match scenarios.


  • Self-Custody Wallet (AI autonomously decides, holds funds, completes payment): Suitable for standardized goods corporate procurement, automated machine-to-machine settlement, primarily for B2B, M2M high-frequency repurchase scenarios;
  • Personal Consumption Scenarios: No need for fund custody; only grant one-time, limited-scope payment tokens; AI can only settle after human confirms the order.


As a C-end promotional headline, "Equipping AI with a Wallet" targets only a very small niche scenario; the real core landing market for this solution is the enterprise backend automation system.


Additional note: Corporate procurement is not entirely standardized goods either. Some procurement decisions also cannot be handled autonomously by AI. Judging law firms, acquisition targets, and core suppliers are strategic choices with significant subjective consequences; like individuals selecting wine, they must be decided by humans personally; self-custody wallets have no use in such scenarios.


This rule applies to all fields: AI-independent wallet custody only plays a role at the standardized goods layer, and standardized business is concentrated within enterprises, with the largest volume and most intensive demand.


The Real Bottleneck Has Never Been Payment


Fund transfer technology has long been mature; there are no bottlenecks in the payment link. The real bottlenecks for AI shopping lie in two other aspects.


First, lack of trusted data sources. The premise for automated judgment is authentic and reliable data. Once the underlying information is distorted, autonomous decision-making AI amplifies the negative impact of false information at machine speed. The proliferation of fake reviews is already an industry-wide open problem. The US Federal Trade Commission introduced new rules in 2024 (effective October 21) explicitly prohibiting fake product reviews, clearly stating that generative AI significantly lowers the threshold for mass-producing fake reviews, with maximum fines per violation up to $51,744; regulatory agencies had issued multiple warning letters by the end of 2025.


The problem of counterfeit physical goods is equally severe. According to OECD and EUIPO 2025 statistics, the global trade volume of counterfeit goods in 2021 was approximately $467 billion, accounting for 2.3% of global trade; counterfeit imports into the EU accounted for 4.7% of total imports, with clothing, footwear, and luxury goods being heavily affected categories, which happen to be experiential consumer goods. Single-item traceability certificates, verifiable authentic reviews, independent third-party authentication, single-item-level transfer records (EU Anti-Counterfeiting Directive and US Drug Supply Chain Security Act have long mandated implementation for drug packaging) are prerequisites for AI to safely judge goods.


Second, human demand definition power cannot be automated. As long as demand standards are defined by humans, subsequent screening, comparison, and settlement can be automated. The act of defining one's own demands is inherently impossible to hand over to machines. If the AI generates demand standards for you, the resulting preferences do not belong to you personally.


Equipping AI agents with wallets only solves the simplest financial link. The direction truly worth in-depth cultivation: automating screening and evaluation safely and controllably, while returning two core rights to humans — defining judgment standards and enjoying the pleasure of making the final choice.


Summary


Finally, it must be emphasized that for experiential consumer goods, once the procurement channel is commoditized, the goods become ubiquitous everywhere. At that point, your product is no longer the good itself; choice is. Platforms need to optimize the standardization level of their own information to facilitate AI retrieval: complete and verifiable traceability, clean structured product data, guiding AI to direct user traffic to their own platform. On this basis, maintain the core advantage that cannot be replaced by automation: exploring new consumption avenues that broaden user aesthetic boundaries and the pleasant experience of ultimately selecting goods. Leave information gathering to AI agents; the platform's core competitiveness focuses on creating a superior choice experience.

Câu hỏi Liên quan

QAccording to the article, what are the two core behaviors of shopping, and which one is difficult to fully delegate to an AI agent?

AAccording to the article, the two core behaviors of shopping are information retrieval and value judgment. Information retrieval, which includes gathering, filtering, comparing, and preliminary sorting, has standardized properties and can largely be delegated to machine agents. Value judgment, which involves determining if a product is good, suitable, or from a trustworthy merchant, is deeply tied to human subjective emotions and is difficult to fully delegate to an AI agent.

QWhat does the article identify as the real dividing line for whether a shopping task can be fully automated by an AI agent?

AThe article identifies that the real dividing line is not whether a product is standardized or personalized, but whether the act of making the choice itself provides experiential value. For purely functional, low-engagement purchases (e.g., printer paper, batteries), the process has no experiential value and is suitable for full AI automation. For experiential or enjoyment-based purchases (e.g., wine, furniture, coats, books), the selection process is part of the core pleasure of consumption, and people are unwilling to fully delegate the final judgment.

QWhat is the key flaw in the 'AI wallet' narrative as explained in the article?

AThe key flaw is that it conflates three separate things: the decision-making entity, the execution entity, and the fund-holding entity. Giving an AI a wallet only solves the fund-holding problem. It only becomes meaningful if the AI also has autonomous decision-making power. For most personal shopping, only limited, one-time payment authorization is needed, not full custody of funds. The narrative places disproportionate importance on the simplest part of the process—payment.

QAccording to the article, what are the two main bottlenecks preventing the widespread adoption of AI shopping agents, apart from payment technology?

AThe two main bottlenecks are: 1) The lack of trusted data sources, including the prevalence of fake reviews and counterfeit goods, which makes automated judgment risky. 2) The inherent inability to automate the definition of human needs and preferences. The right to define one's own evaluation criteria and standards cannot be handed over to a machine without losing personal agency.

QWhere does the article suggest that autonomous AI wallets (with decision-making and fund-holding power) are most applicable?

AThe article suggests that autonomous AI wallets are most applicable in business-to-business (B2B) and machine-to-machine (M2M) contexts. Specifically, they are suited for standardized, high-frequency, low-value corporate procurement (e.g., office supplies, consumables) and automated settlements between machines for services like API calls. These scenarios involve highly standardized goods and剥离了主观体验的 processes, unlike personal experiential consumption.

Nội dung Liên quan

Những mảnh vỡ vĩnh cửu của tiền bạc: Thanh toán bên thứ ba không có tính nguyên tắc đầu tiên

**Tóm tắt: Mảnh vỡ vĩnh cửu của tiền tệ: Ngành thanh toán bên thứ ba không có 'tính nguyên lý đầu tiên'** Ngành thanh toán đang ở một thời điểm then chốt. Stripe, sau khi bỏ lỡ cơ hội IPO trong đại dịch, đang cố gắng mua lại PayPal để bổ sung năng lực thị trường C2C, trong một nỗ lực nhằm kích thích định giá và kể một câu chuyện mới trước khi lên sàn. Tuy nhiên, cuộc chiến trong ngành thanh toán bên thứ ba giống như một trận chiến tiêu hao vĩnh viễn, khó có thể loại bỏ các công ty nhỏ hơn do hai đặc điểm cốt lõi: sự phân mảnh theo quốc gia, ngành và khách hàng; và bản chất là sản phẩm phụ của hệ thống ngân hàng. Stripe đã thử mở rộng từ thị trường nhà phát triển (D) sang doanh nghiệp (B) và người tiêu dùng (C), đồng thời đặt cược vào tương lai thông qua ổn định tiền (stablecoin) và thanh toán tự động (Agentic Payment). Nhưng stablecoin chưa phải là xu hướng thanh toán phổ biến, và các Agent vẫn cần một lối vào hệ thống truyền thống. Giá trị của Stripe giống như một sản phẩm quyền chọn, phụ thuộc vào mức độ thành công của những câu chuyện này. Cơ hội thực sự trong làn sóng stablecoin và Agent có lẽ không nằm ở việc phát hành stablecoin, mà nằm ở hệ thống thanh toán bù trừ (clearing network) hiệu quả cao. Các công ty như Stripe (với Tempo) và Circle (với Arc) đang xây dựng các blockchain và stablecoin của riêng họ, với mục tiêu cuối cùng là thiết lập các mạng lưới thanh toán bù trừ có thể thu hút dòng tiền và giữ lại lợi nhuận, phần nào thoát khỏi sự phụ thuộc hoàn toàn vào hệ thống ngân hàng thương mại truyền thống. Đây có thể là con đường để vượt qua cấu trúc phân mảnh và phụ thuộc vốn có của ngành thanh toán.

marsbit6 phút trước

Những mảnh vỡ vĩnh cửu của tiền bạc: Thanh toán bên thứ ba không có tính nguyên tắc đầu tiên

marsbit6 phút trước

Cuộc Chạy Đua Thông Qua Dự Luật Clarity: Con Đường Thoả Hiệp Hai Đảng Ở Mỹ Gai Góc

Đạo luật Clarity về cấu trúc thị trường tiền mã hóa tại Mỹ đang phải đối mặt với một chặng đường lập pháp đầy chông gai, nơi sự thỏa hiệp giữa hai đảng trở thành yếu tố then chốt cho sự sống còn của nó. Hành trình của dự luật bắt đầu với sự gián đoạn vào tháng 1, khi CEO Coinbase Brian Armstrong làm đảo lộn một thỏa thuận lưỡng đảng tại Ủy ban Ngân hàng Thượng viện. Phải đến bốn tháng sau, nhờ một thỏa hiệp về vấn đề "lợi nhuận" giữa Thượng nghị sĩ Angela Alsobrooks (Dân chủ) và Thom Tillis (Cộng hòa), dự luật mới được đưa vào chương trình nghị sự. Tuy nhiên, các điều khoản về đạo đức lại trở thành điều kiện bắt buộc đối với phe Dân chủ, khiến dự luật cuối cùng được thông qua tại Ủy ban Nông nghiệp Thượng viện chỉ với sự ủng hộ theo đường lối đảng, không có phiếu nào từ phe Dân chủ. Các tranh cãi tiếp tục bùng phát vào tháng 7. Ngoài vấn đề đạo đức, các bất đồng về quy định "lợi nhuận" đã khiến một số nghị sĩ Cộng hòa đứng về phía các ngân hàng lớn, trong khi các cơ quan thực thi pháp luật phản đối mạnh mẽ các điều khoản bảo vệ nhà phát triển. Mối quan tâm chính vẫn là rủi ro tài chính bất hợp pháp và bảo vệ người tiêu dùng. Dù vậy, động lực cho dự luật vẫn đang hình thành. Các cuộc thảo luận giữa các nghị sĩ và quan chức Nhà Trắng đang được tiến hành để tìm kiếm ngôn ngữ thỏa hiệp về đạo đức. Cộng đồng kỳ vọng một bản dự thảo hòa giải giữa hai ủy ban của Thượng viện sẽ sớm được công bố. Tuy nhiên, vẫn còn nhiều nghi ngờ về khả năng đạt được sự ủng hộ đủ rộng rãi từ cả hai đảng. Mục tiêu ngắn hạn của cộng đồng tiền mã hóa có thể là một hành động biểu tượng tại Thượng viện trước kỳ nghỉ hè tháng 8, hoặc hướng tới việc thông qua dự luật tại cả hai viện và được ký thành luật vào năm 2026. Con đường phía trước vẫn còn nhiều trở ngại, nhưng quá trình vận động hành lang kiên trì, giành từng phiếu bầu và từng nghị sĩ, chính là chiến thuật mà ngành công nghiệp này cần theo đuổi.

Foresight News34 phút trước

Cuộc Chạy Đua Thông Qua Dự Luật Clarity: Con Đường Thoả Hiệp Hai Đảng Ở Mỹ Gai Góc

Foresight News34 phút trước

Kalshi Và Polymarket: Mâu Thuẫn Giữa Những Người Sáng Lập Gay Gắt Hơn Tưởng Tượng?

Vào tháng 11/2024, FBI đã đột kích căn hộ của Shayne Coplan, nhà sáng lập Polymarket. Mặc dù công khai đổ lỗi cho chính trị, nhóm của Coplan ngờ rằng đối thủ cạnh tranh chính, Tarek Mansour - CEO của Kalshi, đứng sau. Nguồn tin tiết lộ luật sư Kalshi đã báo cáo vấn đề pháp lý của Polymarket với công tố viên trước đó. Mối thù giữa hai công ty khởi nghiệp tỷ đô này vượt xa cạnh tranh thông thường, trở thành cuộc chiến cá nhân đầy cay độc. Họ tranh giành thị phần, hợp tác, nhân tài, và công kích nhau trên truyền thông. Khác biệt cốt lõi nằm ở triết lý kinh doanh: Kalshi nhấn mạnh tuân thủ quy định Mỹ, trong khi Polymarket hoạt động chủ yếu ở thị trường nước ngoài (offshore) và dễ tiếp cận hơn với người dùng Mỹ. Xung đột leo thang qua nhiều sự kiện: Kalshi vận động hành lang chống lại Polymarket, cố gắng phá hoại thương vụ đầu tư tiềm năng của Polymarket với Intercontinental Exchange (nhưng không thành), và giành lấy hợp đồng tài trợ với Madison Square Garden - địa điểm ưa thích của Coplan. Gần đây, Polymarket đã mua lại một công ty có giấy phép Mỹ (QCX) để ra mắt ứng dụng hợp pháp tại đây. Đến nay, Kalshi dẫn đầu về định giá (220 tỷ USD) và khối lượng giao dịch, nhưng cuộc chiến vẫn tiếp diễn. Áp lực giám sát ngày càng gia tăng với cả hai, đặc biệt sau vụ một binh sĩ Mỹ bị buộc tội sử dụng thông tin nội bộ để đặt cược trên nền tảng offshore của Polymarket.

Foresight News1 giờ trước

Kalshi Và Polymarket: Mâu Thuẫn Giữa Những Người Sáng Lập Gay Gắt Hơn Tưởng Tượng?

Foresight News1 giờ trước

Đi sâu vào khai thác lỗ hổng cầu nối Cardano-BNB của Wanchain – Cách 9 triệu USD NIGHT biến mất trong vài giờ

Wanchain’s Cardano-BNB Bridge, một giao thức chuyển tài sản xuyên chuỗi giữa Cardano và các mạng blockchain khác, đã bị xâm phạm. Kẻ tấn công đã rút cạn khoảng 515 triệu token NIGHT, trị giá 9 triệu USD, từ kho bạc của cầu nối nhờ lợi dụng một lỗ hổng mật mã trong trình xác thực TreasuryCheck. Lỗ hổng này, được gọi là mã hóa thông điệp ký không đơn ánh, cho phép nhiều yêu cầu rút tiền tạo ra cùng một thông điệp mã hóa. Do đó, kẻ xấu có thể tái sử dụng chữ ký hợp lệ từ một giao dịch thật để ủy quyền cho các giao dịch rút tiền giả mạo mà không cần khóa riêng tư của trình xác thực. Sau đó, chúng đã chuyển đổi số token NIGHT bị đánh cắp sang ADA trên mạng Cardano. Wanchain đã ngừng hoạt động cầu nối Cardano-BNB và bắt đầu điều tra, đồng thời xác nhận sự cố chỉ giới hạn ở cầu nối và không ảnh hưởng đến mạng lưới Midnight hoặc blockchain cốt lõi của Cardano. Sự kiện này diễn ra trong bối cảnh hàng loạt vụ khai thác lỗ hổng khác trong không gian crypto gần đây, chẳng hạn như trên Allbridge Core, Ostium và hệ sinh thái BONK, với tổng thiệt hại lên đến hàng chục triệu USD. Tuy nhiên, theo DeFiLlama, tổng tổn thất trong lĩnh vực DeFi tính đến tháng 7/2026 đã giảm mạnh xuống còn khoảng 1 tỷ USD so với 2,135 tỷ USD cùng kỳ năm 2025.

ambcrypto1 giờ trước

Đi sâu vào khai thác lỗ hổng cầu nối Cardano-BNB của Wanchain – Cách 9 triệu USD NIGHT biến mất trong vài giờ

ambcrypto1 giờ trước

Giao dịch

Giao ngay
活动图片