Press Enter to search · ESC to close

AI × Crypto

AI Agents Are Rewriting On-Chain Security: Risk Shifts From Private Keys to Intent and Execution

A joint report from Outpost Research and SlowMist warns that AI agents are shifting on-chain risk from private keys and contract bugs to prompt injection, memory poisoning, and tool supply chains. Incidents involving Grok and Bankrbot show attackers can trigger real transfers by manipulating an agent's output, not by stealing keys. The report calls for redesigned wallets and payment systems with independent authorization, spending limits, whitelists, circuit breakers, and Know Your Agent frameworks.

When the Model, Not the Human, Signs the Transaction

A new joint research report from Outpost Research and SlowMist warns that AI agents are fundamentally changing how on-chain operations work. Instead of a human reviewing and confirming each transaction, agents now interpret intent, call tools, and execute automatically. That shift moves the security perimeter away from private keys, smart contract bugs, and phishing links toward a new set of connective vulnerabilities: prompt injection, memory poisoning, tool-supply-chain attacks, wallet signing, and agentic payment flows.

The Grok and Bankrbot Incidents

Recent incidents involving Grok and Bankrbot illustrate the danger. In these cases, attackers did not need to steal a private key or exploit a contract. They simply manipulated the agent’s output, and that manipulation triggered real on-chain transfers. The lesson is uncomfortable: when an AI agent holds signing authority, the attack surface is no longer cryptographic — it is cognitive and linguistic.

Why the Old Security Model Breaks Down

Traditional Web3 security assumes a human is the final gatekeeper. Users are told to protect seed phrases, verify contract addresses, and avoid suspicious links. But an autonomous agent may hold the keys, hold the session, and act on instructions that a human never sees. Prompt injection can hijack intent. Memory poisoning can corrupt an agent’s long-term context so it misbehaves days later. A compromised tool or API in the agent’s supply chain can silently redirect funds.

  • Prompt injection: malicious text tricks the model into issuing an unauthorized action.
  • Memory contamination: poisoned context persists and distorts future decisions.
  • Tool supply chain: a third-party plugin or API becomes the attack vector.
  • Wallet signing: the agent signs what the model decides, not what the user intended.
  • Agentic payments: automated transfers lack a human checkpoint.

Redesigning Wallets and Payments for the Agent Era

The report argues that wallets and payment systems must be rebuilt around new assumptions. Agents should only be allowed to propose execution plans. A separate, independent rules engine should authorize them, using spending limits, whitelists, circuit breakers, and Know Your Agent (KYA) identity frameworks. In other words, the entity that understands intent must be separated from the entity that grants permission.

The Road Ahead

As AI agents proliferate across DeFi, payments, and on-chain automation, the industry faces a choice. It can treat agents as trusted signers and inherit a wave of novel exploits, or it can build layered authorization that constrains autonomy without killing it. The coming standard will likely blend cryptographic identity, policy engines, and real-time monitoring. Security teams that adapt first will define how the agent economy earns trust.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback