AI agents are ushering in an era of mass crypto hacks: the industry stands on the brink of a new threat

The crypto industry is facing a fundamentally new challenge: autonomous AI agents are drastically lowering the entry barrier for cybercriminals and enabling attacks to scale to unprecedented levels. This topic took center stage at the recent Wyoming Blockchain Symposium, where leading industry experts warned of an impending wave of automated hacks.
Ryan Kirkley, CEO of Global Settlement Network, expressed concern that the industry is too naive about the capabilities of AI. In his words, we are making a fatal mistake in assuming that agents always act for the greater good. The reality is that these systems can be used to simultaneously search for vulnerabilities in the wallets, passwords, and networks of thousands of potential victims.
The Scale of the Threat: The Numbers Speak for Themselves
Analytics show that the problem is no longer theoretical. In the first half of 2026 alone, 207 hacks were recorded—a record figure for any six-month period. Total damages reached $972 million. Notably, the number of attacks doubled compared to 83 incidents a year earlier. Meanwhile, thefts of private keys and seed phrases account for only 15% of incidents but cause about 76% of all losses—a clear sign that attackers are targeting the most valuable assets.
The economics of attacks are changing radically. Previously, hacking an individual user with a small portfolio was unprofitable. Now, a single autonomous system can be unleashed on millions of targets simultaneously, and even major protocol hacks may seem minor compared to the cumulative damage from such campaigns.
The Dual-Use Nature of Technology
It is telling that the same technologies that alarm experts are already being used for defense. In July, the Ethereum Foundation deployed AI agents to analyze critical blockchain components, search for vulnerabilities, and prepare proof-of-concept exploits. However, even in this case, manual verification was required—a significant portion of the results turned out to be false positives.
A separate headache is the integration of agents with financial tools. MetaMask has already opened access to Agent Wallet, where users can delegate operations to an agent within set limits. But a natural question arises: are we creating a new attack vector where compromising an agent means draining the entire wallet? The threat of "prompt injections"—where a hidden malicious instruction in external data triggers an irreversible transaction—is becoming increasingly real.
Not Just Money: Metadata and Trust
There is also a subtler threat. Even in private networks, metadata leaks allow algorithms to reconstruct connections between users, creating a false sense of security. And questions of legal liability for the actions of autonomous systems remain open: if an agent transfers funds to the wrong recipient or performs an illegal operation, who is responsible? On the blockchain, such transactions are irreversible.
My analysis: The industry faces a paradox—we are adopting technologies that simultaneously strengthen and undermine security. The key will be not just technical improvement, but the creation of clear frameworks for accountability and permission management. Without this, the mass adoption of AI agents in finance could lead to catastrophic consequences that we are not yet fully able to comprehend.