Why can crafted content my agent reads authorize my on-chain wallet to transfer funds?
Opportunity
An AI agent with signing authority over a crypto wallet processes arbitrary external content as part of its task context: web pages, emails, documents, API responses. Nothing in today's signing infrastructure separates instruction sources from each other, so a page the agent is asked to summarize can embed hidden transfer instructions the agent interprets as a legitimate task and executes. Wallet standards like ERC-4337 session keys model the problem as what can this key do, not where did this instruction originate. No agent runtime today filters signing decisions by instruction provenance, which means a wallet authorized to move funds is exactly as safe as the most hostile document the agent will ever read.
Why it matters
Agents with on-chain keys are in production now, and every piece of content they process is a potential attack vector against the funds they control.
How I score the opportunity
The Opportunity Score is my own read, not a measurement: how much it hurts, how often it bites, and how little exists to solve it today. Higher means I think it is more worth building.
How much pain it causes when it shows up.
How often people actually run into it.
How little good tooling exists for it today.
More problems worth solving
What does an AI agent's bank account actually look like?
AI x CryptoCan an on-chain organization run by agents avoid becoming a scam machine?
AI x CryptoHow do you prove a photo or a voice is real without a platform vouching for it?
AI x CryptoWhy is on-chain identity either nothing or your entire life?
AI x CryptoHow do I audit which agent acted under my identity across a delegation chain?
AI x CryptoHow do I verify that an AI agent holding my funds is actually solvent?