Autonomous AI agents are radically transforming the economics of cyberattacks on the cryptocurrency sector, and in my assessment, this is one of the most underestimated threats of the current cycle. Participants at the Wyoming Blockchain Symposium reached an alarming conclusion: automation allows attackers to simultaneously scan the wallets, passwords, and networks of thousands of potential victims, reducing the cost of each attack to a minimum.

Ryan Kirkley, CEO of Global Settlement Network, rightly pointed to a fundamental flaw in our perception: the industry stubbornly views agents solely as a benefit. "We act as if agents are always good. I think that's a fatal mistake in almost everything related to such systems today," he emphasized. And this is not paranoia: TRM Labs statistics for the first half of 2026 record 207 hacks—a record figure for any six-month period—with total damages of $972 million.

The key shift I see is the transition from targeted attacks to mass campaigns. Previously, attacking an individual with a small portfolio was economically unfeasible. Now, a single autonomous system can be launched against a vast number of targets in parallel. The number of incidents has doubled compared to the 83 cases in the first half of 2025, with key and seed-phrase thefts accounting for only 15% of incidents but yielding 76% of losses—confirming that attackers are striking at the very heart of the infrastructure.

Trust as the New Currency of Risk

Bill Laboon from the Web3 Foundation astutely noted that reducing "friction" for legitimate users automatically lowers barriers for attackers as well. We already see defenders using agents to hunt for bugs, as the Ethereum Foundation did in July, but the same tools work against us too. Moreover, as the foundation's experience showed, a significant portion of AI results are false positives, adding chaos to an already complex environment.

Of particular concern is the integration of agents directly with financial instruments. Midnight Foundation President Fahmi Syed is right: granting an agent access to credit cards, personal data, and accounts without clear restrictions is a recipe for disaster. Kirkley, meanwhile, raises a deeper question: are we creating a new attack vector where compromising the agent itself allows the entire wallet to be drained? And this is already a reality: MetaMask has opened public access to Agent Wallet, where users set limits, but the risk of "prompt injections" remains critical.

Metadata and the Legal Void

Laboon also reminded us of the false sense of privacy: even in private networks, metadata leaks allow algorithms to reconstruct connections between users. This is an underestimated time bomb. And legal liability for autonomous actions is a complete terra incognita. If an agent transfers funds to the wrong recipient or violates the law, who is responsible? On the blockchain, a transaction cannot be undone.

My conclusion: we are moving toward a point of no return where the speed of AI agent adoption significantly outpaces our understanding of the consequences. While the industry debates trust in LLMs that "still sometimes hallucinate," attackers are already exploiting this uncertainty. Responsibility for security should not rest on the user but on protocols, which must embed protection against automated threats at the level of the underlying architecture.