An AI agent is software that acts on its own to carry out tasks, in crypto's case, moving funds, trading and managing wallets with minimal human supervision. The industry is racing to adopt them. At the Wyoming Blockchain Symposium on Tuesday, a panel of executives argued it is racing past the risks.
"We're acting like agents are always good, and I think that's a really fatal flaw," said Ryan Kirkley, chief executive of Global Settlement Network, on a panel moderated by The Block's CEO. Kirkley warned that AI-enabled attacks could make today's billion-dollar bridge hacks "look like pennies," and sketched why: the same automation that lets an agent execute thousands of legitimate transactions makes attacks economical at any scale. "It used to be so hard to try to hack a person worth $20,000," he said. "Now I can have an agent." He added a question the industry has no answer for yet: if your agent does something illegal, "how do you claw it back?"
The failure modes are new
The panelists' concerns went beyond hijacked wallets. Bill Laboon of the Web3 Foundation pointed to metadata leaks, transaction patterns people will wrongly assume are private, and to the unreliability of the language models many agents are built on: "My LLMs still occasionally hallucinate. I wouldn't want to put my 401k in the hands of that." Automation, he noted, "also means that there is less friction for the bad guys."
The proposed defenses are about limiting blast radius. Fahmi Syed, president of the Midnight Foundation, argued against concentrating permissions in any single agent, calling the idea of one agent holding all of a user's financial power "a scary concept." Fragmented, task-scoped permissions mean a compromised agent can lose only what it was trusted with.
The baseline is already bad
The warning arrived in a fitting week. Maya Protocol halted its network after an attacker chained six software bugs to extract 20.83 bitcoin, about $1.4 million, plus roughly $300,000 in other assets. The exploit inflated a liquidity pool's balance through an uncapped subsidy mechanism, and the protocol's pools lost about $10.9 million in value while its CACAO token fell nearly 89%. Notably, the bugs had reportedly sat undetected for three to four years despite security audits, exactly the kind of long-lived flaw that automated, tireless scanning, by attackers or defenders, will find first.
That is the unsettling symmetry the Wyoming panel kept circling: AI agents are simultaneously the coming attack surface and the most promising audit tool. Whichever side automates faster wins, and today the attackers have fewer constraints.
What it means for investors
For anyone holding crypto through services that adopt agent-based automation, the practical questions are the panel's questions. Does any single system hold enough permissions to drain you? Is there a human checkpoint on large movements? Who is liable when an autonomous system errs? As Richard Shorten of Silvermine Capital Advisors put it, the technology has outrun trust: the challenge is "turning that toolkit into something I trust." Until the industry can answer those questions, the prudent assumption is that agent adoption expands the attack surface faster than it expands the defenses.



