OpenAI Agent Incident Exposes Risks of AI Control Over Crypto Wallets
An OpenAI agent incident highlighted control failures, but no crypto assets were targeted.
Private keys, unrestricted API keys, and withdrawal access should remain beyond AI agents' reach.
A compromised trading key could place or cancel orders, while withdrawal access could move assets. If address management is also enabled, an attacker may be able to add a destination under their control.
The safest approach is limited delegation, not full control. External controls can keep portfolio monitoring and capped payments within defined boundaries across wallets, exchanges, and smart-contract tools.