CertiK says AI agents now trace stolen crypto, but humans still own the mistakes

4 hours ago 7

Blockchain security firm CertiK says autonomous AI agents can now chase stolen crypto across chains, write up suspicious activity reports, and hit the pause button on vulnerable smart contracts.

There is a catch, and it is a very human one. When an agent gets it wrong, a person still takes the blame.

The findings come from CertiK’s Intel3D report, published on October 5, 2026. It focuses on what the industry calls agentic AI: software that acts on its own rather than waiting for someone to type a prompt. Its argument is that crypto attacks now move faster than human analysts can respond.

What the agents actually do

According to the report, AI agents can monitor on-chain transactions continuously. When they spot a threat, they can trigger defensive responses, including pausing a vulnerable contract within the same block window.

CertiK frames this as essential against attacks like flash loans. These exploits borrow huge sums, manipulate a protocol, and repay the loan, all within a single transaction. By the time a human notices, the money is usually gone.

The report also highlights laundering. Stolen funds often travel through mixers, which blend coins together to obscure their origin, and bridges, which move assets between blockchains. CertiK says manual tracing struggles to keep pace with these winding routes.

Beyond tracking, the agents can prepare regulatory reports and activate circuit breakers. A circuit breaker is the crypto equivalent of a stock exchange halting trading during a crash.

The Bybit problem

To show why continuous tracking matters, CertiK pointed to the Bybit exploit. The firm cited that 86.29% of the stolen ETH from that attack was converted to Bitcoin within a month.

The report also references major breaches at Bitget and Liquid Network in September 2026. CertiK uses these incidents to underline a recurring theme: the response window after a hack is brutally short.

Who gets blamed when the bot is wrong

CertiK is explicit that these agents should operate within defined roles and set authority levels. Organizations, it says, must assign a human owner to each agent. That person is accountable for its decisions.

The report names specific failure modes. An agent could freeze a legitimate transaction or file an inaccurate report. Either mistake carries real consequences, from angry customers to regulatory trouble.

To limit that risk, CertiK recommends detailed audit trails, rigorous testing protocols, and capped autonomy. The cap is meant to address errors as well as adversarial attacks, where bad actors try to trick the AI itself.

Background: an auditor’s view of the problem

CertiK built its reputation on smart contract auditing and on-chain forensics. The Intel3D report leans on that experience to argue that agentic AI improves operations in both Web2 and Web3 settings. The report does not name specific crypto tokens using these AI capabilities. It looks at the Web3 security ecosystem as a whole rather than spotlighting individual projects.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article