Runaway AI agents, crypto risks are evolving into a financial control crisis.

By: Sean Stein Smith, Forbes

Compiled by: AididiaoJP, Foresight News

In recent years, the discussion surrounding AI risks has evolved so rapidly that it is hard to keep up. What enterprises face today is no longer trivial issues such as chatbots occasionally spouting nonsense, outputting biased views, or employees accidentally pasting sensitive information into public tools. The real qualitative shift lies in the fact that AI agents now possess the capability to act directly—they can invoke external systems, write code themselves, and even independently execute a whole set of complex multi-step tasks with almost no human oversight.

This transformation brings extremely severe challenges to the financial market, especially the crypto market. Crypto assets trade 24/7, smart contracts execute automatically, and once transactions on the blockchain are confirmed, they are often irreversible. Once these AI agents are connected to wallets, exchanges, DeFi protocols, or payment systems, even a tiny permission vulnerability can directly evolve into irretrievable financial loss. Therefore, agent AI risk is no longer just within the IT department’s remit; it has simultaneously become a core issue of corporate governance and crypto asset control.

Crypto Mechanisms Amplify the Destructive Power of AI Autonomous Actions

A recent incident disclosed by the UK AI Safety Institute highlighted exactly how dangerous this “autonomy” really is. During a cybersecurity assessment test, AI agents took continuous and completely unauthorized actions against real personnel and organizations. Although ultimately stopped in time, this was sufficient to prove that AI agents are fully capable of combining capabilities such as planning decisions, tool invocation, persistent operation, and external access in unexpected ways to execute real-world attacks.

When crypto assets are involved, financial risk is exponentially amplified. An agent capable of accessing private keys or connected wallets can transfer assets, sign malicious contracts, misappropriate collateral, or even interact arbitrarily with decentralized protocols. This is completely different from traditional bank transfers—there is no customer service to help you report a loss urgently, no bank to help you intercept the transaction, and no concept of a “reversal.” Once funds are transferred out, it is almost equivalent to them disappearing forever.

What is more critical is that the crypto market never closes. AI agents can continue operating in the middle of the night, on weekends, or when all employees are asleep. Automated trading or clearing programs could completely turn an originally controllable small mistake into a disaster-level loss within just a few minutes, snowballing rapidly. Therefore, when enterprises assess AI agent risks, the focus should not be on how smart the model is, but on which systems and assets it can access. An agent with mediocre capabilities but wide-open permissions that can directly operate wallets is far more dangerous than a more capable model that is firmly locked in a sandbox. Permission design is becoming a more critical lifeline than model selection.

Internal Controls Must Extend to Every Gap in Wallets and Smart Contracts

Many enterprises have already established a series of traditional internal control measures such as separation of duties, approval limits, access reviews, and change management. The issue lies in the fact that these principles must be implemented without compromise for every AI agent interacting with crypto systems.

No agent should possess “end-to-end” capabilities—for example, completing wallet creation, modifying address whitelists, and initiating transfers simultaneously, all without human intervention throughout the process. High-risk transactions must mandate human approval, and the information received by the approver must be clear and complete: recipient address, asset type, amount, network, Gas fees, and exactly what the transaction is intended to do. Vague, automatically pop-up reminders like “Please confirm system operation” do not count as effective controls at all; they only create an illusory sense of security.

Private keys and signing permissions especially require special protection. Agents must absolutely not be allowed to arbitrarily read seed phrases or signing credentials. Designs such as multi-sig mechanisms, Hardware Security Modules, single transaction limits, and delayed transfers can all effectively reduce the risk of “a vulnerability being exploited and the wallet instantly emptied.” Before interacting with smart contracts, execution must be simulated and strictly verified first; especially when involving unlimited token approvals or contracts from unknown sources, extra vigilance is required.

Enterprises must also establish complete operation logs—what the agent accessed, what instructions it received, which transactions it proposed, which were ultimately successfully on-chain, and whether a human led these operations throughout the process. These records are indispensable for post-incident accountability, security audits, asset protection, and even financial disclosure. Without logs, if something goes wrong, you cannot even clarify accountability.

AI + Crypto Incidents Require Industry-Wide Lesson Sharing

The Linux Foundation and the Open Security AI Alliance have launched the “Shared AI Findings Exchange” (SAFE) mechanism, aimed at helping various organizations learn from real AI security incidents and near misses under conditions of confidentiality. Crypto companies, banks, custodians, exchanges, and audit firms should all actively participate in this kind of information sharing.

The crypto industry has long understood how valuable it is to carefully review hacker attacks, cross-chain bridge collapses, key leaks, and smart contract vulnerabilities. Agent AI adds a new dimension to this old problem—a single incident may simultaneously involve the model itself, prompt design, tool integration, access policies, and the final on-chain transaction. Therefore, a truly useful incident report must clarify all these layers, rather than vaguely dismissing it with a sentence like “The AI had a little problem.”

Boards of directors should now clearly ask: Has agent AI been incorporated into wallet governance, cybersecurity emergency response plans, and upgrade approval processes? Auditors must also consider whether unauthorized agent operations could lead to direct asset loss, balance misstatements, hidden liabilities, or even major defects in the internal control system. Finance teams need to figure out in advance: once a malicious or failed on-chain transaction occurs, how to identify it, how to value it, and how to disclose it truthfully in the reports.

Of course, AI agents do not only pose risks. In the future, they could significantly improve efficiency in crypto compliance, automated reconciliation, fraud detection, and fund management. These benefits are truly achievable. However, the premise is that autonomous capabilities must be paired with sufficiently robust control measures. Otherwise, a small negligence at the code level will instantly become an irretrievable on-chain transfer.

In the crypto world, responsibility must be designed, embedded, and tested before the agent truly gains the ability to act. Whether you are a crypto believer or an AI enthusiast, you should face this point squarely—because once out of control, the outcome is often permanent.