Skip to content
AI x Crypto

Why can crafted content my agent reads authorize my on-chain wallet to transfer funds?

85

Opportunity

An AI agent with signing authority over a crypto wallet processes arbitrary external content as part of its task context: web pages, emails, documents, API responses. Nothing in today's signing infrastructure separates instruction sources from each other, so a page the agent is asked to summarize can embed hidden transfer instructions the agent interprets as a legitimate task and executes. Wallet standards like ERC-4337 session keys model the problem as what can this key do, not where did this instruction originate. No agent runtime today filters signing decisions by instruction provenance, which means a wallet authorized to move funds is exactly as safe as the most hostile document the agent will ever read.

Why it matters

Agents with on-chain keys are in production now, and every piece of content they process is a potential attack vector against the funds they control.

How I score the opportunity

The Opportunity Score is my own read, not a measurement: how much it hurts, how often it bites, and how little exists to solve it today. Higher means I think it is more worth building.

Severity9/10

How much pain it causes when it shows up.

Frequency7/10

How often people actually run into it.

Whitespace8/10

How little good tooling exists for it today.

More problems worth solving