Experts have warned of the risk of mass cryptocurrency hacks using AI agents
8/20/2026, 10:40 AM • Евгения Слив

AI agents can drastically reduce the cost and increase the scale of attacks on cryptocurrency owners, said participants at a blockchain symposium in Wyoming. In their view, automation will enable attackers to simultaneously search for vulnerabilities in the wallets, passwords, and networks of a large number of potential victims. Ryan Kirkley, co‑founder and CEO of Global Settlement Network, believes that the industry too often views autonomous agents only as a useful tool and underestimates the possibility of them being used by attackers. According to him, the industry behaves as if agents are always good, and this is a fatal mistake in almost everything related to such systems today.
According to TRM Labs, in the first half of 2026 alone, the crypto industry faced 207 hacks, which was the highest number for any six‑month period in the company’s statistics. The total damage amounted to 972 million dollars. According to Kirkley, previously it was economically unviable for an attacker to spend a lot of time and resources on attacking an individual with a relatively small crypto portfolio. AI agents are changing this economy: one autonomous system can potentially be launched against a large number of targets simultaneously. The expert suggested that in such a scenario, even current major attacks on crypto protocols may seem small compared to the cumulative damage from large‑scale automated campaigns. TRM data show that attacks are already becoming more widespread. From January to June, their number doubled compared to eighty‑three cases in the same period in 2025. At the same time, infrastructure and operational compromises, including the theft of private keys and seed phrases, accounted for only about fifteen percent of incidents but caused approximately seventy‑six percent of all losses.
Bill Labun, Web3 Foundation’s vice president of technical operations, agreed that the advantages of autonomous systems simultaneously simplify the activities of malicious actors. He noted that friction is becoming less for both good, bad, and neutral participants. The main advantage of AI agents lies in their ability to independently carry out sequences of actions: search for information, access external services, work with code, and use available tools without constant human involvement. The same properties allow them to be used for automated search for targets and vulnerabilities. The practical capabilities of such systems are already being used by defenders. In July, the Ethereum Foundation deployed AI agents to analyze critical components of the blockchain. The systems examined the code, searched for potential vulnerabilities, and prepared materials to confirm the concept. The foundation emphasized the need for manual verification of the results: a significant portion of the candidates found by the agents turned out to be false positives, duplicates, or issues outside the scope of the study..
Separately, the discussion participants discussed the risk of connecting autonomous systems directly to the user’s financial instruments. Midnight Foundation President Fahmi Syed stated that the idea of giving a single agent all the power — including access to credit card data, security information, social security number, and various accounts — seems alarming without clear restrictions. Kirkli considers permission management to be a solvable problem, and he identified the compromise of the agent itself or the environment in which it operates as a more serious threat, raising the question of creating a new attack vector in which the agent can be hijacked and the entire wallet emptied. This problem is becoming more relevant as wallets and crypto services emerge that allow AI to manage assets independently. On August 6, MetaMask opened public access to Agent Wallet. The user can set spending limits, allowed networks, addresses, and protocols for the agent, after which the system independently performs operations within the established limits. MetaMask has also warned about the risk of prompt injections. If an agent simultaneously analyzes data from external sources and is capable of initiating financial transactions, a hidden malicious instruction could potentially lead to an irreversible on‑chain transaction. To reduce the risk, the wallet separates the model’s decision‑making from policy verification and transaction signing.
