Written by: Sean Stein Smith, Forbes
Translated by: AididiaoJP, Foresight News
In recent years, discussions about AI risks have changed so rapidly that it’s overwhelming. What companies face today is no longer just the occasional nonsense from chatbots, biased outputs, or employees accidentally pasting sensitive information into public tools. The real qualitative change is that AI agents now have the capability to take direct action—they can call external systems, write code themselves, and even independently advance a complex multi-step task with minimal oversight.
This shift brings extremely severe challenges to financial markets, especially the crypto market. Crypto assets are traded 24/7, smart contracts are executed automatically, and once transactions on the blockchain are confirmed, they are often irreversible. Once these AI agents are connected to wallets, exchanges, DeFi protocols, or payment systems, even a tiny permission vulnerability could directly lead to irretrievable financial losses. Therefore, agent-based AI risks are no longer just an IT department issue; they have become central to corporate governance and the management of crypto assets.
Crypto mechanisms amplify the lethality of AI autonomous actions
An incident recently disclosed by the UK’s AI Safety Research Institute showcased just how dangerous this "autonomy" can be. During a cybersecurity assessment test, an AI agent took sustained and completely unauthorized actions against real individuals and organizations. Although it was ultimately stopped in time, it sufficiently demonstrated that AI agents are entirely capable of combining planning decisions, tool calls, persistent operations, and external access in unexpected ways to conduct real-world attacks.
When crypto assets are involved, financial risks increase exponentially. An agent with access to private keys or a connected wallet can easily transfer assets, sign malicious contracts, misappropriate collateral, or even interact with decentralized protocols at will. This is fundamentally different from traditional bank transfers—there's no customer service to urgently stop a transaction, no bank that can halt the transfer, and no concept of "reversing" a transaction. Once funds are transferred out, it is almost like they have vanished without a trace.
What’s worse is that the crypto market never sleeps. AI agents can continue operating at night, on weekends, or while all employees are asleep. Automated trading or clearing programs could potentially turn a minor manageable error into a catastrophic loss in just a few minutes. Therefore, when assessing AI agent risks, companies should focus not on how smart the model is, but on which systems and assets it can access. An agent with mediocre abilities but extensive permissions that can directly operate a wallet is far more dangerous than a more capable model securely locked in a sandbox. Permission design is becoming a more critical lifeline than model selection.
Internal controls must extend to every nook and cranny of wallets and smart contracts
Many companies have already established a series of traditional internal control measures, including separation of duties, approval limits, access reviews, and change management. The issue is that these principles must be implemented without compromise for every AI agent interacting with crypto systems.
No agent should have "one-stop" capabilities—such as simultaneously creating a wallet, modifying address whitelists, and initiating transfers all without human intervention. High-risk transactions must mandate real-person approvals, and the approver must receive clear and complete information: the receiving address, asset type, amount, network, gas fees, and the purpose of the transaction. Vague "please confirm system operation" prompts that pop up automatically are not effective controls—they only create an illusion of safety.
Private keys and signing permissions require especially strong protection. Agents must absolutely not be allowed to freely read recovery phrases or signing credentials. Multi-signature mechanisms, hardware security modules, single transaction limits, and delay mechanisms can effectively reduce the risk of "one vulnerability being exploited causing the wallet to be emptied instantly." Before interacting with smart contracts, it is essential to simulate execution and conduct strict verification, especially when dealing with unlimited token authorizations or contracts of uncertain origin; one must be extremely vigilant.
Companies must also establish complete operational logs—documenting what the agent accessed, what commands it received, which transactions it proposed, which were ultimately successfully recorded on the blockchain, and whether a real person was in control throughout these operations. These records are indispensable for post-event accountability, security audits, asset protection, and even financial disclosures. Without logs, incidents cannot be properly understood.
AI and Crypto accidents necessitate industry-wide sharing of lessons
The Linux Foundation and the Open Security AI Alliance have already launched the "Shared AI Incident Exchange" (SAFE) mechanism aimed at helping organizations learn from real AI security incidents and risks while maintaining confidentiality. Crypto companies, banks, custodians, exchanges, and audit firms should actively participate in such information sharing.
The crypto industry has long understood the value of carefully reviewing hacker attacks, cross-chain bridge collapses, key leaks, and smart contract vulnerabilities. Agent-based AI adds a new dimension to this old problem—an incident can involve the model itself, prompt design, tool integration, access policy, and the final on-chain transaction simultaneously. Therefore, truly useful incident reports must clearly articulate all these layers, rather than vaguely stating, "there was a problem with the AI."
The board should now clearly ask: Is agent-based AI included in wallet governance, network security emergency plans, and upgrade approval processes? Auditors should consider whether unauthorized agent actions could lead to direct asset losses, balance discrepancies, hidden liabilities, or even significant flaws in the internal control system. The finance team needs to think ahead: once a malicious or failed on-chain transaction occurs, how will it be identified, assessed, and truthfully disclosed in the financial statements?
Of course, AI agents also bring opportunities. They have the potential to greatly enhance the efficiency of crypto compliance, automated reconciliations, fraud detection, and fund management in the future. These benefits are genuinely expected. However, the premise is that autonomous capabilities must be matched with sufficiently strong control measures. Otherwise, a minor oversight at the code level could quickly turn into an irretrievable on-chain transfer.
In the crypto world, responsibility must be designed, embedded, and tested before agents genuinely gain the ability to act. Whether you are a believer in crypto or an advocate of AI, this reality must be faced—because once it goes out of control, the consequences are often permanent.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。