CertiK AI Agents Track Stolen Crypto but Humans Bear the Blame
CertiK, a blockchain security firm, has introduced autonomous AI agents capable of tracing stolen cryptocurrency across different blockchain networks. These agents can also generate reports on suspicious activities and temporarily halt vulnerable smart contracts. However, the system still relies on human oversight, as individuals remain accountable for any errors made by the AI.
The findings were detailed in CertiK’s Intel3D report, published on October 5, 2026. The report emphasizes the need for agentic AI, software that operates independently rather than awaiting user prompts, to combat the increasing speed of crypto attacks. The AI agents monitor transactions continuously and can trigger defensive actions, such as pausing a vulnerable contract within the same block window.
CertiK highlights the importance of this technology in preventing exploits like flash loans, where attackers manipulate protocols within a single transaction. The report also addresses the challenge of tracking stolen funds through mixers and bridges, which obscure the origin of assets and complicate manual tracing efforts.
The Bybit exploit serves as a case study, with 86.29% of the stolen ETH converted to Bitcoin within a month. The report references other major breaches at Bitget and Liquid Network in September 2026, underscoring the critical need for rapid response in crypto security.
CertiK stresses that AI agents must operate within defined roles and authority levels, with a human owner assigned to each agent. This ensures accountability for any mistakes, such as freezing legitimate transactions or filing inaccurate reports. The firm recommends detailed audit trails, rigorous testing, and capped autonomy to mitigate risks and potential adversarial attacks.