AI agent Security is becoming a major cause of worry in crypto and Web3 as more and more autonomous systems get direct access to wallets, trading tools, APIs and blockchain protocols.
A new research paper released on May 20th from Google, Gray Swan AI, EmbraceTheRed, along with several universities, warned that AI agents should not be treated as a trust-worthy software.
Instead, the researchers say there’s a need to build security right into the system because AI agents can be manipulated, taken advantage of or tricked into doing something that puts users at risk.
This warning is particularly timely as AI-powered crypto tools are spreading fast across trading, DeFi, token launches and wallet management. In fact, Circle CEO Jeremy Allaire predicted a few months back that there’ll be billions of AI agents working on behalf of users within 5 years.
Researchers Say Ignore The Idea That AI Agents Are Trusted
The paper, titled Agent Security is a Systems Problem, says that the current AI safety approach is focusing so much on building up the strength of the AI model itself while not paying enough attention to the infrastructure that surrounds it.
The researchers wrote:
“The AI model powering the agent must be treated as an untrusted component.”
According to the paper, just relying on traditional ‘prompt guardrails’ isn’t going to be enough especially when AI agents start gaining access to different systems and tools like browsers, wallets, APIs, cloud systems, memory layers, or execution tools.
The researchers identified three main protections that can help cut down on attacks.
First, AI systems must clearly separate trusted instructions from untrusted. That means keeping untrusted data away from trusted instructions.
This reduces the risk of hidden malicious prompts being injected into files, web pages, or conversations.
Second, AI agents should only be given minimum permissions that they need instead of unrestricted access to sensitive systems.
Third, data movement should be controlled by the surrounding infrastructure rather than the agent itself. That prevents agents from leaking out confidential information, or sending users’ assets off to unsafe destinations.

Crypto Platforms Are Getting Increasingly Vulnerable to AI Agent Security Risks
The crypto sector may be especially vulnerable because so many AI agents are now interacting directly with financial systems.
AI-powered tools are already being used for automated trading, token launches, DeFi execution, smart contract analysis and wallet management. Several startups are now building fully autonomous Web3 assistants that can execute blockchain transactions without needing human approval to do so.
But this creates new risks and new potential attack points.
Just recently, the AI-powered crypto trading assistant Bankr had to temporarily turn off transactions because attackers had somehow managed to get access to at least 14 wallets connected to the system. Some security researchers even think that the platform might have fallen victim to an exploit of its own agent infrastructure.
Google and security firms are warning that there is a huge escalation in AI-driven attacks. Google recently identified what it described as one of the first AI-assisted zero-day cyberattacks, where AI systems helped detect previously unknown vulnerabilities.
Gray Swan AI also reported that every frontier AI model tested during a large prompt-injection competition could be compromised without users noticing. The exercise involved more than 272,000 attack attempts across 13 advanced AI models.
For crypto platforms, those risks become way more severe because a compromised AI agent can control assets directly.
Web3 Developers Are Calling for Stronger AI Agent Security Safeguards
Security experts are getting louder with their warnings about the need for stricter controls before giving AI agents financial control.
Aaron Ratcliff, the lead on attribution at blockchain intelligence firm Merkle Science, has been saying this for a while now that giving AI direct access to wallets adds new trust issues to systems originally designed to remove trust assumptions.
He is of the opinion that AI agents should be able to flag front-running trades, enforce slippage protection, identify dodgy tokens, and check contracts before executing trades. He also stressed the need for prompt sandboxing and defenses against injection attacks.
Meanwhile, Sahara AI co-founder Sean Ren said properly configured model context protocols can act as “gatekeepers” between AI systems and wallets.
That way, agents can prepare transactions or check balances without giving them unrestricted access.
Governments are starting to take notice too. The Five Eyes intelligence alliance has just warned businesses against throwing agentic AI into sensitive environments without security and strict identity management in place.
Industry analysts now think AI security is going to be one of the biggest battles of the next Web3 cycle.

Why AI Agent Security Is Suddenly Becoming a Big Deal
The AI boom has companies rushing to deploy autonomous systems, but security standards are struggling to keep up.
A recent report found that 80% of the Fortune 500 companies are already trying out AI agents in live environments. But only 14% have even finished the whole security approval. That gap is causing serious worry in finance and crypto.
For blockchain networks, the stakes are higher because AI agents are now operating in systems where things can’t be undone. A compromised agent doesn’t just leak data, it can move money, change contracts, or execute trades instantly.
Conclusion
AI agent security is fast becoming one of the biggest conversations in crypto. As autonomous systems get better at doing things without human input, researchers are warning that they can’t just be treated like trusted systems.
The latest research from Google, Gray Swan AI, and some top security teams adds that AI agents need to be controlled through system-level protections, limited permissions, and credible infrastructure safeguards.
Glossary
AI Agent: A software that can do things on its own and make decisions without constantly human input.
Prompt Injection: An attack where malicious instructions are hidden inside data or prompts to manipulate AI behavior.
Decentralized Finance (DeFi): Decentralized finance applications operating on blockchain networks.
Zero-Day Attack: A cyberattack exploiting a previously unknown vulnerability.
Web3: Blockchain-based internet infrastructure focused on decentralization and digital ownership.
Frequently Asked Questions About AI Agent Security
Why is AI agent security becoming a concern?
There’s a growing risk that if these AI agents get cracked, they could cause real chaos especially when they’re controlling wallets, APIs, and trading systems.
What did the researchers say about AI agent security?
They recommended treating AI agents as untrusted systems and enforcing security at the infrastructure level.
What does this mean for the crypto platforms we use?
If AI agents get hacked, it could mean that funds get siphoned off, or dodgy trades get made, or even sensitive info gets leaked to the wrong people.
Are any companies already relying on AI?
Yes, a lot of crypto and enterprise platforms are already using AI agents to automate tasks, from trading to basic operations.
References

