A hooded figure interacts with a digital
AI

CertiK says agentic AI is turning crypto security into an autonomous workforce

The Intel3D report argues same-block response and real-time compliance are feasible, but liability stays with human operators.

By Elliot Marsh6 min read

CertiK’s Intel3D report says “agentic AI” is moving from assisting analysts to executing crypto security and compliance work with limited human intervention. The firm frames it as an “AI security workforce” that can investigate threats, trace funds, and even trigger incident response, while pushing accountability and operational risk back onto the teams that deploy it.

CertiK’s ‘AI Security Workforce’ Moves From Alerts to Action

CertiK’s Intel3D report describes “agentic AI” as a shift from models that flag anomalies or summarize alerts to systems that can plan and execute multi-step work on their own. In CertiK’s framing, these agents can call external tools and APIs, gather evidence, take actions in live environments, and then evaluate outcomes before choosing the next step.

That autonomy is why CertiK calls the model an “AI security workforce,” not another dashboard. The report’s core claim is operational: autonomous systems are increasingly doing work that used to sit with human analysts across cybersecurity, anti-money laundering, and compliance, including investigating threats, tracing funds, and acting on incidents with limited human involvement.

The pressure for this move is speed. CertiK’s report says flash loan exploits can drain protocols “within seconds,” while stolen assets can move through multiple addresses, bridges, and mixing services “within hours.” Under CertiK’s methodology, crypto losses reached $768.4 million in September across 97 incidents, and totaled roughly $2.68 billion in 2026 by the end of September.

CertiK’s point is not that audits or analysts are obsolete. It is that the escalation path is the bottleneck, and the market is drifting toward systems that can do more than raise a hand.

Same-Block Monitoring, Fund Tracing, and Compliance: Where Agents Are Being Pointed

On smart contract security, CertiK argues agentic systems can take on tasks that previously required experienced engineers. The report describes agents moving through a contract’s call graph, analyzing state changes across multiple contracts and external calls, and checking for known vulnerability classes including reentrancy (repeated calls before state updates), oracle manipulation (corrupting a price or data feed), access control failures, and unsafe upgrade mechanisms.

CertiK also ties agentic AI to formal verification, the practice of proving a program meets mathematically defined specifications. The report says agents can generate formal specifications and test them against contract behavior, reducing manual work for formal methods engineers. Humans remain in the loop, but the job shifts toward verifying AI-generated findings, investigating new economic or game-theoretic attack methods, and probing blind spots in automated systems.

Where the report gets more market-relevant is live monitoring and response. CertiK says automated security can extend beyond audits into transaction monitoring that watches pending and confirmed transactions for exploit patterns like flash loan attacks, oracle manipulation, and abnormal liquidity withdrawals. In “more advanced setups,” CertiK says detection can trigger an automated response within the same block window, including pausing a vulnerable function, activating a circuit breaker (a safety pause/limit), or freezing a compromised administrator key.

Fund tracing is the other leg. CertiK says agents can continuously follow stolen assets as they move, update address clusters as new activity appears, and infer common control using signals like transaction timing, overlapping counterparties, and gas-fee behavior. The report argues this matters because cross-chain laundering breaks traditional tooling that analyzes networks in isolation. CertiK says agentic systems can combine multi-chain activity into a single investigation and follow funds through bridges and cross-chain swaps.

Compliance is treated as a parallel automation track. CertiK says “Know Your Address” and “Know Your Transaction” screening can be performed in real time before transactions settle, flagging exposure to illicit assets earlier in the flow. The report also says regulatory reporting can be automated by pulling onchain data, reconciling it with offchain records, and preparing reports for obligations including Travel Rule data sharing and stablecoin reserve attestations. CertiK points to regulatory pressure as a driver, citing an earlier Skynet report that found AML penalties exceeded $900 million in H1 2025.

Controls, Failure Modes, and the Liability Problem When Agents Get Permissions

CertiK’s report is explicit that autonomy creates a new risk surface once agents are allowed to touch production controls. The firm flags incorrect decisions, high-confidence errors, prompt injection (maliciously manipulating inputs so the agent follows unsafe instructions), and direct manipulation of agents that have permissioned access to sensitive systems.

The failure mode is not abstract. If an agent can pause contracts, freeze keys, or approve actions, then a compromised input channel becomes a protocol risk, not an “AI quality” issue. CertiK also warns that human reviewers can become less likely to catch errors as trust builds from routine successes.

The liability point is blunt: accountability does not move with the automation. CertiK says AI systems do not hold legal or operational responsibility, leaving organizations deploying them and the humans configuring and supervising them responsible for outcomes. The report says this requires complete audit trails of agent inputs, reasoning, and actions, clear limits on what agents can do independently, testing against adversarial manipulation, escalation thresholds, and a named human owner for each agent.

Two adoption signals sit outside pure security tooling. CertiK notes that autonomous agents can become blockchain users themselves, holding assets and executing trades or treasury operations, which creates a need to audit agent-driven onchain behavior and preserve records of inputs and actions. As an example of shipping product, MetaMask launched an AI Agent Wallet in June 2026 that allows autonomous agents to execute swaps, perpetual futures trades, and other onchain transactions under user-established controls.

My Take: Autonomy Is a Security Upgrade Only If Teams Treat Agents Like Privileged Infrastructure

The threshold that matters is whether “same-block response” stays a slide-deck capability or becomes a disclosed, permissioned control path that major protocols and exchanges are willing to run in production. CertiK’s report makes a credible case that post-incident analysis is losing the race to exploit velocity, but it also admits the uncomfortable part: the moment an agent can pause a function or freeze a key, prompt injection stops being an AI parlor trick and becomes a direct treasury and uptime risk.

If real deployments start publishing guardrails like audit trails, scoped permissions, escalation thresholds, and named owners, the setup starts to look structural rather than narrative-driven. If the next wave of examples is false positives that pause contracts, or manipulated agents taking privileged actions, the market will treat “AI security workforce” as another operational hazard that teams bolted onto production too early.

Sources