By : Mohammad Shahid
Publisher : beincrypto
Date : August 27, 2026

Who is Responsible When an AI Agent Loses Your Money?

On May 4, a message hidden in Morse code helped trigger a six-figure crypto transfer. It passed through two connected AI systems. One was Elon Musk’s Grok, the chatbot built by Elon Musk’s xAI. The other was Bankrbot, a crypto agent that could make payments from a linked wallet. 

The attacker first sent the wallet a digital membership token that unlocked Bankr’s payment tools. Grok then decoded the message, and Bankrbot treated the response as a payment order. It transferred an estimated $150,000 to $200,000.

A Morse-Code Message Became a Six-Figure Payment

Now, why is this concerning? Because the case highlights a six-figure exploit involving just two AI agents. One AI produced text. Another treated it as permission to spend.

If we look at the scale of AI agentic payments today, such scenarios could be a nightmare for the future of Agentic Finance. 

Keyrock counted 176 million on-chain agent payments worth $73 million through April 2026. The median payment sat between $0.01 and $0.10, while 76% fell below $0.30. Small payments become a large control problem when software can make them continuously.

Agent-payment volume is high even while individual payments remain tiny. Source: Keyrock

The pattern is moving into mainstream payment infrastructure. Mastercard launched Agent Pay for Machines in June for high-frequency, low-value payments, while Google and Visa are developing standards for agents to prove identity and authority.

BeInCrypto asked Rodrigo Coelho, CEO of Edge & Node; Nitin Gaur, Head of Institutions at Nethermind; and Francesco Andreoli, Director of Developer Relations at MetaMask, who carries the risk. 

Coelho was direct.

“The company that deployed it. There is no version of this where responsibility lands on the model,” said Rodrigo Coelho, the CEO of AI and Web3 infrastructure developer Edge & Node.

California has already put that principle into law. AB 316, effective since January, prevents a defendant who developed, modified, or used AI from arguing that the system autonomously caused the alleged harm. Causation and foreseeability still matter.

The Receipt Is Not the Permission

An on-chain transaction proves money moved. It does not prove the agent had a valid mandate to move it.

“Most companies deploying agents today could not actually prove what their agent was authorized to do. They can show you the transaction. It happened on a chain and the record is public and permanent. What they cannot show you is the permission that sat behind it,” said Coelho.

Gaps may include who delegated authority, which policy applied, what information the agent read and whether the payment stayed within its limits. A wallet address answers none of those questions.

Nitin Gaur from Nethermind said the dispute turns on the mandate.

“What decides a dispute is authority evidence. Show the agent acted inside a valid, signed, time-bounded mandate and this resolves like any other authorized payment.”

Google’s AP2 uses cryptographically signed mandates to record user intent. Visa’s Trusted Agent Protocol lets approved agents present digital signatures proving identity and associated authorization. 

Mastercard adds credentialing and programmatically enforced limits. The rails differ, but the design goal is shared: permission has to travel with the payment.

Put the Limits Where the Agent Cannot Reach

A mandate still fails if the agent can rewrite it, approve its own request or hold unrestricted signing power. Coelho draws the boundary at the private key.

“The agent should not hold the keys. It should be able to propose a payment, and a separate system decides whether that payment is permitted,” said Coelho.

Francesco Andreoli from MetaMask makes the same point about prompts: 

“The controls that work are the ones the agent cannot reach, if your policy lives in the prompt, it isn’t a policy, it’s a suggestion to a system we’ve repeatedly watched get talked into things.”

In practice, that means segregated funds, hard transaction and daily limits, approved counterparties, fast revocation, and a tested kill switch. An independent system checks the rules before signing.

The tools feeding agents create another risk. Snyk scanned 3,984 public agent skills in February and found at least one security issue in 36.82%. It confirmed 76 malicious payloads involving credential theft, backdoors, or data exfiltration.

Snyk found security problems across a large share of public agent skills. Source: Snyk ToxicSkills research

Gaur sees prompt injection as the dominant pattern: “Prompt injection is the dominant pattern: an agent takes instruction from untrusted content it was asked to read and executes it as though the principal had asked.”

A defensible audit trail therefore needs the agent identity, signed mandate, policy version, transaction, source data, and any approved exception, written when payment occurs. The chain provides one part.

Gaur’s standard is shorter: “Provable, revocable and bounded.”

Without those properties, companies are left with an immutable receipt for a decision they cannot defend.

The post Who is Responsible When an AI Agent Loses Your Money? appeared first on BeInCrypto.

Read more

Latest News

Genius Group plans $827M Bitcoin, ...
By Lawrence Mondal
Publisher : crypto
Date : August 27, 2026
Bitcoin Privacy Wallet Sparrow Iss...
By Jason Nelson
Publisher : decrypt
Date : August 27, 2026
Aave V4 deposits hit record $806M ...
By Lawrence Mondal
Publisher : crypto
Date : August 27, 2026
Trump Media Drops ‘Truth Predict’ ...
By Graham Stone
Publisher : news
Date : August 27, 2026
Mirae Asset targets $109B digital ...
By Lawrence Mondal
Publisher : crypto
Date : August 27, 2026