![]() |
| By Beth Canova |
We’ve warned you before about hackers using AI.
They use it to write better phishing emails.
To clone voices.
And even to fake videos of people in your contacts to really sell the scam.
But now, we may be facing something new: AI agents that can cause harm without explicit instruction.
OpenAI says agents built on its platform may have caused harm or gained access to systems at more than 100 groups. The company is now going through about 50 petabytes of data to learn how far the problem went.1
That’s a huge amount of data.
And it points to a new kind of online risk.
When AI Does More Than Talk
Most of us know AI as a tool that answers questions.
You type something.
It gives you an answer.
An AI agent can go much further. Agents can be given tools that let them take action.
Related story: AI Assistants Are Spending Your Money — These Companies Profit From Making It Safe
They can browse the web. They can work with data. And they can carry out tasks with less help from a person.
That power is useful. But it can also create new risks.
According to Quartz, OpenAI found cases where its models used internet access in ways that were not intended.
OpenAI also said some agents did not have the right limits in place.2
The review began after an even more serious event.
Quartz reports that AI agents escaped a controlled test setting and breached the AI site Hugging Face. Internal data and login details were exposed.
OpenAI called it the worst event of its kind that it had found.
Its review then grew. Agents also interacted with U.S. government websites in ways OpenAI did not expect. One even gained access to an Australian Medicare statistics database without permission.
OpenAI says most of the cases it has found so far were low risk. But its review could take months.
And it’s not the only AI platforms that’s experienced AI acting unexpectedly. Anthropic, Meta (META) and Google have also reported rogue AI agents during their own breach attempts.3
And that’s a hard pill to swallow.
It means not only is AI becoming a powerful tool for intentional hacking, making attacks cheaper, more efficient and more convincing …
It’s also breaking cybersecurity barriers all on its own.
For an asset class that was created to be trustless and live entirely online, that’s a big vulnerability for crypto projects. And for users and investors like us.
Which means we all need to improve our online security. That’s why I’ve compiled the four core rules you should follow to boost your crypto safety.
Rule No. 1: Verify, Don’t Trust (Even If It Looks Real)
This may be the biggest change AI brings.
A fake email used to have clues: Bad spelling. Odd wording. A strange logo.
Not anymore.
We saw that after the recent Trezor data breach.
Not only was buyers’ sensitive data — including names, emails and physical addresses — stolen. But AI also allowed the hackers to send out phishing emails from an official Trezor domain.
That made the emails look real. Mark Gough even said the fakes were very impressive.
This was possible thanks to AI.
It can write clean copy. It can copy a person’s style. And it can create fake images, voices and experts.
The lesson is simple.
Don’t trust something just because it looks real. In true crypto fashion, you’ll want to verify it for yourself.
If your bank, broker, crypto exchange or wallet company sends an urgent message, don’t use the link in that message.
Go to the site yourself.
Use the app you already have.
Or call a number you know is real.
Rule No. 2: Guard Your Keys
This matters for everyone.
But it matters even more if you own crypto.
The recent Trezor breach exposed names, email addresses, phone numbers, home addresses and order data. Notably, though, the company said that private keys and wallet backups were not exposed.
Still, criminals now have data that can help them build a very good scam. One convincing enough to trust them with your keys.
That is exactly why no reputable company will ever ask you for your keys.
Neither will they ask you to connect your wallet to a website to verify it.
If someone is asking, that’s a red flag that should catch your attention.
While this rule was designed to keep your crypto safe, taking this approach with any sensitive information reduces your exposure to harm across the board.
Rule No. 3: Layer Your Security Plan
Hardware wallets can add strong protection for your crypto keys. But don’t mistake them for an ironclad defense.
The recent Coldcard case showed why.
The weakness in those wallets involved how some older models created their recovery phrases. It was a vulnerability users couldn’t have known … or prepared for.
That meant you could have done everything right … and still been at risk.
The larger lesson is more useful than the details: Your security should have layers.
That means keeping your wallet software and firmware up to date. And revoking permissions if you do connect to any platforms (more on that in Rule 4).
If you hold a large amount of crypto, storing your holdings among several devices may be another layer to consider. This way, your crypto is kept safe by more than one seed phrase.
Finally, for larger holdings, a multisig setup may also make sense. That would mean you’d need multiple keys to move your funds.
Rule No. 4: Clean Up Old Wallet Access
There is another risk that is easy to forget: old permissions.
When you use a DeFi site, you may give it permission to access an asset in your wallet.
And if that’s where your interaction ends, that permission may stay open long after you stop using the site.
That’s exactly how the BarnBridge attack was able to access so many wallets. Many of which were not connected at the time of the hack.
An attacker was able to target old wallet approvals. In about 12 minutes, $776,575 was taken from 92 wallets.
So, check your wallet permissions from time to time.
Remove access for sites you no longer use.
And be careful when looking for tools to do this.
Type the trusted site address yourself rather than clicking an ad, search result or social media reply.
Bottom Line: Make Yourself a Harder Target
You can’t stop AI from getting better. And you can’t stop every data breach.
But you can make yourself a tougher target.
Use a hardware security key instead of text-message login codes when you can. Keep long-term crypto offline. Clean up old wallet permissions. Never share a seed phrase.
And most of all, verify before you trust.
That last step may matter more than ever. Because the next fake email may have perfect grammar.
The next fake expert may look and sound real.
And the next cyber threat may not even need a person sitting at a keyboard.
AI is changing the game.
Our security habits need to change with it.
Stay safe,
Beth Canova
1https://qz.com/openai-rogue-ai-agents-100-organizations-100226
2https://qz.com/openai-rogue-ai-agents-100-organizations-100226
3https://www.cnn.com/2026/09/26/tech/openai-agents-rogue-government-websites

