0.05%
2.01%
9.07%
BTC
$80,282.04
0.12%
0.76%
7.52%
ETH
$2,511.93
0.01%
1.30%
8.56%
BNB
$712.49
0.02%
3.44%
14.86%
XRP
$1.45
0.14%
8.28%
24.10%
SOL
$109.25
0.07%
0.72%
0.05%
TRX
$0.33778860
0.17%
2.94%
9.93%
DOGE
$0.08918592
0.02%
3.89%
11.29%
LINK
$11.95
0.16%
1.45%
4.52%
ADA
$0.21390128
0.09%
0.02%
4.12%
LTC
$49.93
0.05%
2.01%
9.07%
BTC
$80,282.04
0.12%
0.76%
7.52%
ETH
$2,511.93
0.01%
1.30%
8.56%
BNB
$712.49
0.02%
3.44%
14.86%
XRP
$1.45
0.14%
8.28%
24.10%
SOL
$109.25
0.07%
0.72%
0.05%
TRX
$0.33778860
0.17%
2.94%
9.93%
DOGE
$0.08918592
0.02%
3.89%
11.29%
LINK
$11.95
0.16%
1.45%
4.52%
ADA
$0.21390128
0.09%
0.02%
4.12%
LTC
$49.93
   /       /       /    Who is Responsible When an AI Agent Loses Your Money?

Who is Responsible When an AI Agent Loses Your Money?

Who is Responsible When an AI Agent Loses Your Money?

On May 4, a message hidden in Morse code helped trigger a six-figure crypto transfer. It passed through two connected AI systems. One was Elon Musk’s Grok, the chatbot built by Elon Musk’s xAI. The other was Bankrbot, a crypto agent that could make payments from a linked wallet. 

The attacker first sent the wallet a digital membership token that unlocked Bankr’s payment tools. Grok then decoded the message, and Bankrbot treated the response as a payment order. It transferred an estimated $150,000 to $200,000.

A Morse-Code Message Became a Six-Figure Payment

Now, why is this concerning? Because the case highlights a six-figure exploit involving just two AI agents. One AI produced text. Another treated it as permission to spend.

If we look at the scale of AI agentic payments today, such scenarios could be a nightmare for the future of Agentic Finance. 

Keyrock counted 176 million on-chain agent payments worth $73 million through April 2026. The median payment sat between $0.01 and $0.10, while 76% fell below $0.30. Small payments become a large control problem when software can make them continuously.

The pattern is moving into mainstream payment infrastructure. Mastercard launched Agent Pay for Machines in June for high-frequency, low-value payments, while Google and Visa are developing standards for agents to prove identity and authority.

BeInCrypto asked Rodrigo Coelho, CEO of Edge & Node; Nitin Gaur, Head of Institutions at Nethermind; and Francesco Andreoli, Director of Developer Relations at MetaMask, who carries the risk. 

Coelho was direct.

“The company that deployed it. There is no version of this where responsibility lands on the model,” said Rodrigo Coelho, the CEO of AI and Web3 infrastructure developer Edge & Node.

California has already put that principle into law. AB 316, effective since January, prevents a defendant who developed, modified, or used AI from arguing that the system autonomously caused the alleged harm. Causation and foreseeability still matter.

The Receipt Is Not the Permission

An on-chain transaction proves money moved. It does not prove the agent had a valid mandate to move it.

“Most companies deploying agents today could not actually prove what their agent was authorized to do. They can show you the transaction. It happened on a chain and the record is public and permanent. What they cannot show you is the permission that sat behind it,” said Coelho.

Gaps may include who delegated authority, which policy applied, what information the agent read and whether the payment stayed within its limits. A wallet address answers none of those questions.

Nitin Gaur from Nethermind said the dispute turns on the mandate.

“What decides a dispute is authority evidence. Show the agent acted inside a valid, signed, time-bounded mandate and this resolves like any other authorized payment.”

Google’s AP2 uses cryptographically signed mandates to record user intent. Visa’s Trusted Agent Protocol lets approved agents present digital signatures proving identity and associated authorization. 

Mastercard adds credentialing and programmatically enforced limits. The rails differ, but the design goal is shared: permission has to travel with the payment.

Put the Limits Where the Agent Cannot Reach

A mandate still fails if the agent can rewrite it, approve its own request or hold unrestricted signing power. Coelho draws the boundary at the private key.

“The agent should not hold the keys. It should be able to propose a payment, and a separate system decides whether that payment is permitted,” said Coelho.

Francesco Andreoli from MetaMask makes the same point about prompts: 

“The controls that work are the ones the agent cannot reach, if your policy lives in the prompt, it isn’t a policy, it’s a suggestion to a system we’ve repeatedly watched get talked into things.”

In practice, that means segregated funds, hard transaction and daily limits, approved counterparties, fast revocation, and a tested kill switch. An independent system checks the rules before signing.

The tools feeding agents create another risk. Snyk scanned 3,984 public agent skills in February and found at least one security issue in 36.82%. It confirmed 76 malicious payloads involving credential theft, backdoors, or data exfiltration.

Gaur sees prompt injection as the dominant pattern: “Prompt injection is the dominant pattern: an agent takes instruction from untrusted content it was asked to read and executes it as though the principal had asked.”

A defensible audit trail therefore needs the agent identity, signed mandate, policy version, transaction, source data, and any approved exception, written when payment occurs. The chain provides one part.

Gaur’s standard is shorter: “Provable, revocable and bounded.”

Without those properties, companies are left with an immutable receipt for a decision they cannot defend.

Source: BeInCrypto

28-08-2026
Cryptocurrencies / Cryptocurrency News

Cryptocurrency News

Grok Build vs. Claude Code and Codex: developers criticized xAI's toolGrok Build vs. Claude Code and Codex: developers criticized xAI's toolElon Musk’s Grok Bot Has a $1 Million Domain ProblemElon Musk’s Grok Bot Has a $1 Million Domain ProblemxAI released Grok Imagine Video 1.5: what to know about the AI video generatorxAI released Grok Imagine Video 1.5: what to know about the AI video generatorCourt dismissed xAI's lawsuit against OpenAI over trade secretsCourt dismissed xAI's lawsuit against OpenAI over trade secrets

Random quote about money

"Когда доходит до денег, единственное, до чего большинство людей могут додуматься, - это вкалывать изо всех сил."

Роберт Кийосаки

Interesting posts in other sections of the blog

Information

Users of Guests are not allowed to comment this publication.

Latest articles

all articles →
Schiff Calls MSTR Death Spiral, While Saylor Rides Bulls, MSTR Hits $137Cryptocurrency NewsSchiff Calls MSTR Death Spiral, While Saylor Rides Bulls, MSTR Hits $137Peter Schiff renews his MSTR death spiral warning as Michael Saylor answers with a bullish AI video near $137.28-08-2026The Foreign Owners Behind Trump’s $4 Billion Stablecoin BankCryptocurrency NewsThe Foreign Owners Behind Trump’s $4 Billion Stablecoin BankEric Trump signed a passivity pledge for a stablecoin bank whose biggest stake traces to an Abu Dhabi power broker.28-08-2026Ahead of Fed Meeting, Former Governor Miran Says Rate Hike Would Be ‘Weird'Cryptocurrency NewsAhead of Fed Meeting, Former Governor Miran Says Rate Hike Would Be ‘Weird'Stephen Miran says a Fed rate hike now would be a mistake, blaming distorted PCE inflation data for masking real progress.28-08-2026Bithumb Wins Lawsuit After Mistakenly Crediting Users With 620,000 BTC: ReportCryptocurrency NewsBithumb Wins Lawsuit After Mistakenly Crediting Users With 620,000 BTC: ReportThe ruling adds to Bithumb’s effort to recover funds after a February error gave hundreds of accounts vastly overstated Bitcoin balances.28-08-2026Elon Musk and Morgan Stanley’s SpaceX Predictions Are 7 Years ApartCryptocurrency NewsElon Musk and Morgan Stanley’s SpaceX Predictions Are 7 Years ApartMusk's SpaceX revenue forecast beats Wall Street by seven years. See what the stock actually prices in.28-08-2026Who is Responsible When an AI Agent Loses Your Money?Cryptocurrency NewsWho is Responsible When an AI Agent Loses Your Money?On May 4, a message hidden in Morse code helped trigger a six-figure crypto transfer. It passed through two connected AI systems. One was Elon Musk’s Grok, the28-08-2026Silver Price Faces Make-or-Break Week Ahead of Jackson Hole Fed SpeechCryptocurrency NewsSilver Price Faces Make-or-Break Week Ahead of Jackson Hole Fed SpeechSilver stalls at $68.88 Fibonacci resistance as the weekly MACD nears its first bullish crossover since May 2025.27-08-2026FRIEND Explodes Over 1,600% After Machi Big Brother Proposes $1M TakeoverCryptocurrency NewsFRIEND Explodes Over 1,600% After Machi Big Brother Proposes $1M TakeoverTrading volume surged nearly 95,000% in 24 hours as traders rushed back into the dormant token, pushing its price up by over 1,600%.27-08-2026Genius Group Sets $2B Dual Treasury Target Months After Liquidating Bitcoin HoldingsCryptocurrency NewsGenius Group Sets $2B Dual Treasury Target Months After Liquidating Bitcoin HoldingsBitcoin Magazine Genius Group Sets $2B Dual Treasury Target Months After Liquidating Bitcoin Holdings Genius Group has announced a new plan to buy bitcoin —27-08-2026
Sign inMasterInvest
RUENUK