Out-of-Control AI Agents: Crypto Risks are Evolving into Financial Control Crises.
Written by: Sean Stein Smith, Forbes
Compiled by: AididiaoJP, Foresight News
In recent years, discussions about AI risks have changed so rapidly that it’s hard to keep up. Today, companies are facing issues far beyond the occasional nonsensical output from chatbots, biased viewpoints, or employees accidentally pasting sensitive information into public tools. The real transformation lies in the fact that AI agents now possess the capability to take direct action—they can call external systems, write their own code, and even independently execute a complex series of multi-step tasks with little oversight.
This shift poses severe challenges for financial markets, particularly the crypto market. Crypto assets are traded 24/7, smart contracts execute automatically, and once transactions on the blockchain are confirmed, they are often irreversible. Once these AI agents are integrated into wallets, exchanges, DeFi protocols, or payment systems, even a minor permission vulnerability can lead to irreversible financial losses. Therefore, the risks associated with agent-based AI are no longer just an IT department concern; they have become a core issue of corporate governance and crypto asset management.
A recent incident disclosed by the UK’s AI Security Research Institute has highlighted just how dangerous this "autonomy" can be. During a cybersecurity assessment test, an AI agent took continuous and completely unauthorized actions against real individuals and organizations. Although it was ultimately stopped in time, it clearly demonstrated that AI agents are fully capable of combining planning, decision-making, tool invocation, persistent operation, and external access in unexpected ways to carry out real-world attacks.
When crypto assets are involved, financial risks can escalate exponentially. An agent that can access private keys or connected wallets can easily transfer assets, sign malicious contracts, misappropriate collateral, or even interact arbitrarily with decentralized protocols. This is fundamentally different from traditional bank transfers—there are no customer service representatives to help you urgently freeze an account, no bank to stop a transaction, and no concept of "reversal." Once funds are transferred, it is almost equivalent to sinking into the ocean.
Worse yet, the crypto market never sleeps. AI agents can continue to operate in the middle of the night, on weekends, or while all employees are asleep. Automated trading or clearing programs can easily turn a manageable small mistake into a catastrophic loss in just a few minutes. Therefore, when assessing AI agent risks, companies should focus not on how intelligent the model is, but on which systems and assets it can access. An agent with mediocre capabilities but extensive permissions, capable of directly operating wallets, is far more dangerous than a more capable model that is tightly confined within a sandbox. Permission design is becoming a more critical lifeline than model selection.
Many companies have already established a series of traditional internal control measures such as segregation of duties, approval limits, access reviews, and change management. The problem is that these principles must be implemented without compromise for every AI agent interacting with crypto systems.
No agent should possess "one-stop" capabilities—such as simultaneously creating wallets, modifying address whitelists, and initiating transfers without any human intervention. High-risk transactions must require mandatory human approval, and the approver must receive clear and complete information: recipient address, asset type, amount, network, Gas fees, and the purpose of the transaction. Vague, automatically generated prompts like "Please confirm system operation" do not constitute effective control and only create an illusion of security.
Private keys and signing permissions require special protection. Agents must never be allowed to read mnemonic phrases or signing credentials at will. Multi-signature mechanisms, hardware security modules, single transaction limits, and delayed transactions can effectively reduce the risk of "one vulnerability being exploited, leading to an instant wallet drain." Before interacting with smart contracts, simulations must be executed and strictly verified, especially when it involves unlimited token authorizations or contracts of unknown origin, requiring utmost caution.
Companies must also establish comprehensive operational logs—what the agent has accessed, what instructions it received, what transactions it proposed, which ones were successfully recorded on-chain, and whether a human was involved throughout these operations. These records are indispensable for post-incident accountability, security audits, asset protection, and even financial disclosures. Without logs, it is impossible to clarify responsibilities when issues arise.
The Linux Foundation and the Open Security AI Alliance have launched the "Shared AI Discovery Exchange" (SAFE) mechanism, aimed at helping organizations learn from real AI security incidents and risks while maintaining confidentiality. Crypto companies, banks, custodians, exchanges, and auditing firms should actively participate in such information sharing.
The crypto industry has long understood the value of carefully reviewing hacker attacks, cross-chain bridge collapses, key leaks, and smart contract vulnerabilities. Agent-based AI adds a new dimension to this old problem—an incident may simultaneously involve the model itself, prompt design, tool integration, access policies, and the final on-chain transaction. Therefore, truly useful incident reports must clarify all these layers, rather than vaguely stating, "AI had some issues."
The board should now clearly ask: Has agent-based AI been included in wallet governance, network security emergency plans, and upgrade approval processes? Auditors should also consider whether unauthorized agent operations could lead to direct asset losses, balance misreporting, hidden liabilities, or even significant flaws in the internal control system. The finance team must think ahead: once a malicious or failed on-chain transaction occurs, how to identify it, how to value it, and how to disclose it truthfully in financial statements.
Of course, AI agents are not solely about risks. They could significantly enhance the efficiency of crypto compliance, automated reconciliation, fraud detection, and fund management in the future. These benefits are genuinely promising. But the premise is that autonomous capabilities must be matched with sufficiently robust control measures. Otherwise, a small oversight at the code level could quickly turn into an irretrievable on-chain transfer.
In the crypto world, responsibilities must be designed, embedded, and tested before agents truly gain the ability to act. Whether you are a believer in crypto or an advocate of AI, this is a point that must be acknowledged—because once out of control, the consequences are often permanent.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.




![[SCAN 2026 Final Interview] ⑤EDCCS: Chinese University Students Compete in Blockchain Tracking Contest for the First Time](/public-static/3_1a7f0699b3.png?format=avif)






Today’s WEEX TradFi Daily Brief covers softer consumer data weighing on the broader market, a modest rebound in oil and precious metals supported by geopolitics, and the upcoming Fabrinet earnings report, helping you quickly capture stock-token trading opportunities.


















