discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

AI agents must be treated as untrusted systems: Researchers

Researchers from Google and others say AI-agent security should be built into the whole system, not just the model, to reduce attacks.

By Stephen Katte·May 26·cointelegraph.com·2 min read

Intelligence analysis by GPT-5.4 Mini

AI agents must be treated as untrusted systems: Researchers
Image: cointelegraph.com

A new paper argues AI agents should be treated like untrusted parts of a larger computer system, with security controls around permissions, data flow, and instructions. The warning matters for crypto because AI agents are already being used to trade, manage wallets, and interact with protocols.

Why it matters

Crypto users are starting to hand AI agents real authority over wallets and transactions, which raises the cost of a security mistake. The article highlights a systems-level approach that could reduce the risk of prompt injection, data leakage, and unauthorized transfers.

Researchers are saying an AI helper should not be trusted like a careful human. It should be treated more like a tool that can make mistakes if someone tricks it.

The safe way is to put fences around it. It should only do small jobs, keep secret things in locked boxes, and not be able to run wild with wallet money.

That matters in crypto because these helpers can trade coins or move funds. If the rules are weak, it is like giving a robot a house key and hoping it never opens the wrong door.

Analysis

What the researchers argue

A paper released on May 20 by researchers from Google, Gray Swan AI, EmbraceTheRed, and several universities says AI-agent security should be treated as a systems security problem. Their core point is that making the model itself more robust is not enough. The agent has to be surrounded by controls that assume it can be fooled.

The three controls they emphasize

The researchers say three mechanisms could eliminate a large share of attacks. First, agents should clearly separate instructions from untrusted data so malicious text cannot masquerade as commands. Second, agents should only get the minimum permissions needed for a task, rather than broad access. Third, the wider system, not the agent, should control where sensitive data can go.

Why this lands in crypto

The article ties the research to a growing crypto use case: AI agents that trade, launch tokens, and interact with Web3 services on behalf of users. That makes security failures more dangerous because the agent may touch wallets and protocols directly. Cointelegraph cites a recent case in which Bankr disabled transactions after identifying an attacker who had gained access to at least 14 wallets. The piece also quotes prior comments from Merkle Science and Sahara AI leaders, who argue that safe setup, sandboxing, approval gates, and limited permissions are essential before an AI agent should handle funds.

Key points

  • Researchers from Google and partners say AI-agent security should be treated as a systems problem, not just a model problem.
  • They argue agents need clear separation between instructions and untrusted data to reduce injection-style attacks.
  • They recommend minimum permissions and system-level control over sensitive data flows.
  • The article connects the warning to crypto use cases where AI agents can touch wallets, trades, and protocols.
  • A recent Bankr incident is cited as an example of how agent-linked systems can become security risks.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentssecurityresearchcryptotechautomation

Author

Stephen Katte

Intelligence analysis by

GPT-5.4 Mini

Published

May 26, 2026

Source

cointelegraph.com

Share

Topics

ai-agentssecurityresearchcryptotechautomation

Related

More from this desk

investing finance money SEC banking bitcoin cryptocurrency Paul Atkins CLARITY Act
Jul 29·decrypt.co

SEC Ready to Provide Crypto Rules if Clarity Act Flounders: Chair Atkins

SEC Chairman Paul Atkins stated that the agency is prepared to create its own rules for the crypto market if the Clarity Act fails to pass Congress. He emphasized the importance of a statute to provide future-proof certainty to the market.

Morgan Stanley offices (Sven Piper/Unsplash)
Jul 29·coindesk.com

The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs

Morgan Stanley executives say the era of traditional 9-to-5 banking is ending as markets move toward 24/7 trading and settlement. They expect tokenized assets to bring blockchain technology to mainstream investors before many buy cryptocurrencies directly.

clarity act
Jul 29·bitcoinmagazine.com

Banking Lobby CEO Talks Crypto Clarity Act as Senators Race To Pass Bill

The CEO of the American Bankers Association, Rob Nichols, has said that the banking lobby wants the Clarity Act to succeed — but small edits to the bill still need to be made. The bill was passed last year by the House of Representatives but has been in deadlock after ban…

Brale CEO Ben Milne (Brale, modified by CoinDesk)
Jul 29·coindesk.com

Stablecoin firm Brale says new protocol can remove a major hurdle to scaling custom tokens

Stablecoin infrastructure firm Brale introduced ION Protocol, an interoperability system that lets participating stablecoins move across blockchains by burning tokens on one chain and minting them on another. The testnet debut comes amid rapid growth and fragmentation in …