Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Who Bears Responsibility When AI Agents Mishandle Crypto Payments?

A six-figure exploit involving AI systems highlights accountability gaps in autonomous agent payments. Experts say responsibility lies with deploying companies, not AI models, and proper controls require cryptographic mandates and segregated fund limits.
1 week ago 31 views
Who Bears Responsibility When AI Agents Mishandle Crypto Payments?

A Morse-code message routed through two connected AI systems triggered a six-figure cryptocurrency transfer in May. The attack exploited interaction between Grok, a chatbot, and Bankrbot, a crypto agent with wallet access. The attacker sent a membership token to unlock payment tools, Grok decoded the message, and Bankrbot executed a transfer estimated between $150,000 and $200,000.

The incident exposes a fundamental problem as AI agents increasingly handle payments. According to Keyrock data, 176 million on-chain agent payments worth $73 million occurred through April 2026. While most individual payments fell below $0.30, the volume creates control challenges when software executes transactions continuously.

Legal and Operational Responsibility

California law already addresses the question of who bears responsibility. AB 316, effective since January, prevents defendants who developed, modified, or used AI from claiming the system acted autonomously. Legal experts and infrastructure developers agree: responsibility lands with the deploying company.

"The company that deployed it. There is no version of this where responsibility lands on the model," said Rodrigo Coelho, CEO of Edge & Node.

However, on-chain transaction records do not prove an agent had valid authorization. "Most companies deploying agents today could not actually prove what their agent was authorized to do," Coelho noted. Documentation gaps include who delegated authority, which policies applied, and whether payments stayed within limits.

Mandates and Cryptographic Control

Industry standards now emerging address these gaps. Google's AP2 uses cryptographically signed mandates to record user intent. Visa's Trusted Agent Protocol lets approved agents present digital signatures proving identity and authorization. Mastercard's Agent Pay for Machines adds credentialing and programmatically enforced limits.

The common design principle: permission must accompany the payment itself. "What decides a dispute is authority evidence. Show the agent acted inside a valid, signed, time-bounded mandate and this resolves like any other authorized payment," said Nitin Gaur, Head of Institutions at Nethermind.

Technical Safeguards

Effective controls require segregation between agent decision-making and execution authority. Agents should propose payments but not hold the private keys or approve their own requests. Independent systems must verify that transactions comply with policy before signing.

"The controls that work are the ones the agent cannot reach," said Francesco Andreoli, Director of Developer Relations at MetaMask. "If your policy lives in the prompt, it isn't a policy, it's a suggestion to a system we've repeatedly watched get talked into things."

Practical defenses include segregated funds, hard transaction and daily limits, approved counterparties, fast revocation, and tested kill switches. A complete audit trail should document agent identity, signed mandate, policy version, transaction details, source data, and any approved exception at the time payment occurs.

Security Risks in Agent Tools

Tools that feed agents present additional vulnerabilities. Snyk scanned 3,984 public agent skills in February and found security issues in 36.82%. The research confirmed 76 malicious payloads involving credential theft, backdoors, or data exfiltration. Prompt injection emerged as the dominant attack pattern, where agents execute instructions from untrusted content as though the principal had authorized them.

Gaur summarized the standard for defensible agent payments: "Provable, revocable and bounded." Without these properties, companies retain immutable records of transactions they cannot defend.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $78,523.00-0.85% EthereumETH $2,483.18-0.39% Tether USDUSDT $0.99990.00% BNBBNB $752.12+1.68% XRPXRP $1.42+1.66% USDCUSDC $1.0000-0.01% SolanaSOL $103.07-0.82% TRONTRX $0.3382+1.05% HyperliquidHYPE $84.41-1.06% ZcashZEC $1,167.22+1.15%
Prices by Coinranking. Informational only.