Mass deployment of AI agents is a disaster waiting to happen, says CertiK CEO
CertiK says autonomous AI agents are being deployed too quickly, creating major security risks around files, credentials and funds.
Intelligence analysis by GPT-5.4 Mini
CertiK CEO Ronghui Gu argues the current AI agent boom is built on a bad trust model: agents are being given sensitive access before being properly isolated or vetted. The result, he says, is a growing security debt that can be abused through prompt injection, malicious plugins and automated on-chain scams.
A new kind of robot helper can read files, use tools and even touch money. CertiK says that is risky if the helper is given too much power too soon.
The danger is a bit like handing a stranger the keys to a house because they look friendly. A trick hidden in a note or webpage could make the helper do the wrong thing without anyone noticing.
CertiK says these helpers should be locked down first and checked very carefully. That matters in crypto because some helpers can move coins or make trades very quickly.
Analysis
The core warning
CertiK CEO Ronghui Gu says the rush to deploy autonomous AI agents is creating a dangerous security gap. In his view, many agents are being trusted too early, before developers isolate them or check the tools they can access. Once an agent can read local files, use credentials or interact with financial systems, it can act like a powerful insider rather than a harmless assistant.
How the risk shows up
Gu says the problem is not just traditional malware. A major concern is prompt injection, where hidden instructions are embedded in ordinary-looking content such as a webpage, PDF or email. If an unisolated agent processes that content, it may treat the malicious instructions as part of its task and then leak data or trigger unauthorized transfers. CertiK also says it found malicious skills, fake installers and lookalike packages on open agent hubs, which can influence behavior without relying on classic virus signatures.
Why crypto is exposed
The article ties this to on-chain automation, where AI agents may trade, pay or manage wallets without constant human oversight. Gu says CertiK has observed short-lived scams designed to attack other AI systems and automated trading tools, sometimes lasting only minutes or hours before disappearing. His prescription is a strict Zero Trust setup: isolate the agent, scan its tools and verify every command and dependency instead of assuming a local app is safe by default.
Key points
- CertiK warns that many AI agents are being deployed before they are properly isolated or vetted.
- The firm says agents with access to files, credentials and financial tools can become insider threats.
- Prompt injection can hijack an agent through hidden instructions in emails, PDFs or webpages.
- CertiK says it found malicious skills, fake installers and lookalike packages on agent hubs.
- The company recommends a Zero Trust model for AI agents that verifies every tool and command.



