0.15%
1.58%
9.75%
BTC
$80,215.65
0.44%
0.35%
8.06%
ETH
$2,512.49
0.24%
0.68%
8.53%
BNB
$711.89
0.30%
2.35%
14.49%
XRP
$1.45
0.74%
8.47%
24.72%
SOL
$109.30
0.00%
0.54%
0.19%
TRX
$0.33773563
0.51%
2.00%
10.96%
DOGE
$0.08912249
0.47%
2.92%
11.56%
LINK
$11.92
0.27%
1.10%
8.01%
ADA
$0.21440148
0.21%
0.63%
4.50%
LTC
$50.05
0.15%
1.58%
9.75%
BTC
$80,215.65
0.44%
0.35%
8.06%
ETH
$2,512.49
0.24%
0.68%
8.53%
BNB
$711.89
0.30%
2.35%
14.49%
XRP
$1.45
0.74%
8.47%
24.72%
SOL
$109.30
0.00%
0.54%
0.19%
TRX
$0.33773563
0.51%
2.00%
10.96%
DOGE
$0.08912249
0.47%
2.92%
11.56%
LINK
$11.92
0.27%
1.10%
8.01%
ADA
$0.21440148
0.21%
0.63%
4.50%
LTC
$50.05
   /       /       /    Who is Responsible When an AI Agent Loses Your Money?

Who is Responsible When an AI Agent Loses Your Money?

Who is Responsible When an AI Agent Loses Your Money?

On May 4, a message hidden in Morse code helped trigger a six-figure crypto transfer. It passed through two connected AI systems. One was Elon Musk’s Grok, the chatbot built by Elon Musk’s xAI. The other was Bankrbot, a crypto agent that could make payments from a linked wallet. 

The attacker first sent the wallet a digital membership token that unlocked Bankr’s payment tools. Grok then decoded the message, and Bankrbot treated the response as a payment order. It transferred an estimated $150,000 to $200,000.

A Morse-Code Message Became a Six-Figure Payment

Now, why is this concerning? Because the case highlights a six-figure exploit involving just two AI agents. One AI produced text. Another treated it as permission to spend.

If we look at the scale of AI agentic payments today, such scenarios could be a nightmare for the future of Agentic Finance. 

Keyrock counted 176 million on-chain agent payments worth $73 million through April 2026. The median payment sat between $0.01 and $0.10, while 76% fell below $0.30. Small payments become a large control problem when software can make them continuously.

The pattern is moving into mainstream payment infrastructure. Mastercard launched Agent Pay for Machines in June for high-frequency, low-value payments, while Google and Visa are developing standards for agents to prove identity and authority.

BeInCrypto asked Rodrigo Coelho, CEO of Edge & Node; Nitin Gaur, Head of Institutions at Nethermind; and Francesco Andreoli, Director of Developer Relations at MetaMask, who carries the risk. 

Coelho was direct.

“The company that deployed it. There is no version of this where responsibility lands on the model,” said Rodrigo Coelho, the CEO of AI and Web3 infrastructure developer Edge & Node.

California has already put that principle into law. AB 316, effective since January, prevents a defendant who developed, modified, or used AI from arguing that the system autonomously caused the alleged harm. Causation and foreseeability still matter.

The Receipt Is Not the Permission

An on-chain transaction proves money moved. It does not prove the agent had a valid mandate to move it.

“Most companies deploying agents today could not actually prove what their agent was authorized to do. They can show you the transaction. It happened on a chain and the record is public and permanent. What they cannot show you is the permission that sat behind it,” said Coelho.

Gaps may include who delegated authority, which policy applied, what information the agent read and whether the payment stayed within its limits. A wallet address answers none of those questions.

Nitin Gaur from Nethermind said the dispute turns on the mandate.

“What decides a dispute is authority evidence. Show the agent acted inside a valid, signed, time-bounded mandate and this resolves like any other authorized payment.”

Google’s AP2 uses cryptographically signed mandates to record user intent. Visa’s Trusted Agent Protocol lets approved agents present digital signatures proving identity and associated authorization. 

Mastercard adds credentialing and programmatically enforced limits. The rails differ, but the design goal is shared: permission has to travel with the payment.

Put the Limits Where the Agent Cannot Reach

A mandate still fails if the agent can rewrite it, approve its own request or hold unrestricted signing power. Coelho draws the boundary at the private key.

“The agent should not hold the keys. It should be able to propose a payment, and a separate system decides whether that payment is permitted,” said Coelho.

Francesco Andreoli from MetaMask makes the same point about prompts: 

“The controls that work are the ones the agent cannot reach, if your policy lives in the prompt, it isn’t a policy, it’s a suggestion to a system we’ve repeatedly watched get talked into things.”

In practice, that means segregated funds, hard transaction and daily limits, approved counterparties, fast revocation, and a tested kill switch. An independent system checks the rules before signing.

The tools feeding agents create another risk. Snyk scanned 3,984 public agent skills in February and found at least one security issue in 36.82%. It confirmed 76 malicious payloads involving credential theft, backdoors, or data exfiltration.

Gaur sees prompt injection as the dominant pattern: “Prompt injection is the dominant pattern: an agent takes instruction from untrusted content it was asked to read and executes it as though the principal had asked.”

A defensible audit trail therefore needs the agent identity, signed mandate, policy version, transaction, source data, and any approved exception, written when payment occurs. The chain provides one part.

Gaur’s standard is shorter: “Provable, revocable and bounded.”

Without those properties, companies are left with an immutable receipt for a decision they cannot defend.

Source: BeInCrypto

28-08-2026
Криптовалюти / Новини у світі криптовалют

Новини у світі криптовалют

У Grok-бота Ілона Маска проблема з доменом за $1 млнУ Grok-бота Ілона Маска проблема з доменом за $1 млнxAI випустила Grok Imagine Video 1.5: що потрібно знати про ШІ-генератор відеоxAI випустила Grok Imagine Video 1.5: що потрібно знати про ШІ-генератор відеоСуд відхилив позов xAI до OpenAI про комерційну таємницюСуд відхилив позов xAI до OpenAI про комерційну таємницюGrok Build проти Claude Code і Codex: розробники розкритикували інструмент xAIGrok Build проти Claude Code і Codex: розробники розкритикували інструмент xAI

Випадкова цитата про гроші

"Благосостояние государства обеспечивают не те деньги, которые оно ежегодно отпускает чиновникам, а те, что оно ежегодно оставляет в карманах граждан."

Йожеф фон Этвёш

Цікаві записи в інших розділах блогу

Інформаційне повідомлення

Відвідувачі, які знаходяться в групі Гості, не можуть залишати коментарі до даної публікації.

Останні матеріали

усі статті →
Who is Responsible When an AI Agent Loses Your Money?Новини у світі криптовалютWho is Responsible When an AI Agent Loses Your Money?On May 4, a message hidden in Morse code helped trigger a six-figure crypto transfer. It passed through two connected AI systems. One was Elon Musk’s Grok, the28-08-2026Silver Price Faces Make-or-Break Week Ahead of Jackson Hole Fed SpeechНовини у світі криптовалютSilver Price Faces Make-or-Break Week Ahead of Jackson Hole Fed SpeechSilver stalls at $68.88 Fibonacci resistance as the weekly MACD nears its first bullish crossover since May 2025.27-08-2026FRIEND Explodes Over 1,600% After Machi Big Brother Proposes $1M TakeoverНовини у світі криптовалютFRIEND Explodes Over 1,600% After Machi Big Brother Proposes $1M TakeoverTrading volume surged nearly 95,000% in 24 hours as traders rushed back into the dormant token, pushing its price up by over 1,600%.27-08-2026Genius Group Sets $2B Dual Treasury Target Months After Liquidating Bitcoin HoldingsНовини у світі криптовалютGenius Group Sets $2B Dual Treasury Target Months After Liquidating Bitcoin HoldingsBitcoin Magazine Genius Group Sets $2B Dual Treasury Target Months After Liquidating Bitcoin Holdings Genius Group has announced a new plan to buy bitcoin —27-08-2026Trump Just Mentioned Micron Stock, But Its Down 5% This WeekНовини у світі криптовалютTrump Just Mentioned Micron Stock, But Its Down 5% This WeekTrump hailed Micron's $10 billion lab plan a week late. MU stock had already priced it in and fell 5%.27-08-2026Japanese Bitcoin Industry Unveils ‘Aurora’ to Let Global Anime Fans Support $2 Trillion Yen SpaceНовини у світі криптовалютJapanese Bitcoin Industry Unveils ‘Aurora’ to Let Global Anime Fans Support $2 Trillion Yen SpaceBitcoin Magazine Japanese Bitcoin Industry Unveils ‘Aurora’ to Let Global Anime Fans Support $2 Trillion Yen Space Payment rails haven't kept pace for27-08-2026Anthropic IPO Could Come in September, But It Has a Massive Risk FactorНовини у світі криптовалютAnthropic IPO Could Come in September, But It Has a Massive Risk FactorAnthropic could list in late September and plans to let early backers sell stock in the IPO, unlike SpaceX.27-08-2026Solana (SOL) Reclaims $100: Is It Time for a Parabolic Rally?Новини у світі криптовалютSolana (SOL) Reclaims $100: Is It Time for a Parabolic Rally?"Looking good as long as that $98 level is being held," one popular X user claimed.27-08-2026No Fork Required: Bitcoin’s First Quantum-Safe Transaction Just HappenedНовини у світі криптовалютNo Fork Required: Bitcoin’s First Quantum-Safe Transaction Just HappenedBitcoin Magazine No Fork Required: Bitcoin’s First Quantum-Safe Transaction Just Happened The first post-quantum Bitcoin transaction was broadcast this week.27-08-2026
УвійтиMasterInvest
RUENUK