Autonomous AI agents are moving from supporting role to operator across crypto security, anti-money-laundering and compliance work — investigating threats, tracing stolen funds across chains, and acting on live incidents with limited human intervention — according to a new CertiK Intel3D report.
The change CertiK describes is structural: agentic systems can reason through multiple steps, call external tools and APIs, collect evidence, and take actions in live environments before assessing the results. The firm frames the result as an emerging "AI security workforce" in which humans shift toward supervision, quality control and accountability.
From Assistant to Operator
The pressure driving adoption is speed. Flash-loan exploits drain protocols within seconds of initiation, and stolen assets fragment across addresses, bridges and mixers within hours. CertiK's own loss accounting — $768.4 million across 97 incidents in September, roughly $2.68 billion for 2026 through the end of the month — frames a response window that human analysts alone increasingly cannot cover.
In smart contract security, the report says agentic systems now traverse a contract's call graph, analyze state changes across multiple contracts and external calls, and hunt for vulnerability classes including reentrancy, oracle manipulation, access-control flaws and unsafe upgrade mechanisms. Agents are also being applied to formal verification, generating specifications and testing them against contract behavior. The report is explicit that human auditors remain in the loop — their work increasingly centers on verifying machine-generated findings, investigating economic and game-theoretic attack methods, and probing the blind spots of the automated systems themselves. The distinction matters: agentic scanning is analysis tooling, not a substitute for a human-reviewed audit engagement.
Live operations extend further. CertiK describes monitoring pending and confirmed transactions for flash-loan attacks, oracle manipulation and abnormal liquidity withdrawals — with advanced setups triggering an automated response in the same block window: pausing a vulnerable function, tripping a circuit breaker, or freezing a compromised administrator key without waiting for a human.
Tracing and Compliance
On the investigation side, the report says agents can follow assets continuously as they move rather than reconstructing paths after the fact, update address clusters using transaction timing, overlapping counterparties and gas-fee behavior, and merge activity across chains into a single investigation. It cites prior CertiK research documenting that 86.29% of the ETH stolen in the Bybit exploit was converted to Bitcoin within one month through mixers, bridges and over-the-counter brokers.
Compliance work is automating in parallel: Know-Your-Address and Know-Your-Transaction screening performed before transactions settle, and agents assembling regulatory reports — Travel Rule data sharing, stablecoin reserve attestations — from on-chain and off-chain records.
The New Attack Surface
The report's sharpest section concerns what autonomy costs. Agents can produce incorrect conclusions while expressing high confidence — a wrong transaction trail in an AI-drafted suspicious activity report, or a false assurance that a specification blocks a vulnerability — and human reviewers grow less likely to catch such errors as trust in routine output builds. Because security agents hold permissions to interact with sensitive systems, prompt injection or manipulation of their inputs could cause an agent to approve a fraudulent transaction or disable a legitimate control.
Attackers, CertiK notes, have the same capabilities: AI-accelerated vulnerability discovery, automated reconnaissance and more convincing social engineering. And when agents themselves become blockchain users — holding assets, executing trades, managing treasuries, as MetaMask's June AI Agent Wallet release anticipates — organizations may need to audit an agent's on-chain behavior and preserve records of what information it used and how it decided.
CertiK's recommendations are procedural rather than technical: complete logs of agent inputs, reasoning and actions; hard limits on independent decisions; adversarial testing against manipulation; and a named human owner accountable for each agent's performance and failures. Liability for autonomous actions remains unresolved across jurisdictions — which is, for now, the strongest argument for keeping humans in the loop.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.