📈 Get daily crypto insights that make you smarter about your money

CertiK Says Agentic AI Is Joining the Crypto Security Workforce, From Audits to Real-Time Defense

Agentic AI has started taking over work once handled directly by human analysts across cybersecurity, anti-money-laundering and compliance, with autonomous systems now investigating threats, tracing funds and acting on security incidents with limited human intervention, according to a new CertiK Intel3D report.

The change goes beyond using artificial intelligence to flag suspicious activity or summarize information for analysts. CertiK describes agentic systems that can reason through multiple steps, call external tools and APIs, collect evidence, take actions in live environments and assess the results before deciding what to do next. The security firm calls the emerging model an AI security workforce, in which autonomous systems operate within defined roles while human experts move toward supervision, quality control and accountability.

From security assistant to operator

For much of the past decade, AI in cybersecurity and compliance played a supporting role. Machine learning systems could identify anomalies, while natural language tools summarized alerts or prepared reports that people ultimately reviewed and acted upon.

CertiK’s report argues that line is now blurring. In a security operations center, an autonomous system could investigate an unusual login, retrieve the device fingerprint and location history, compare the information against threat intelligence, decide whether an account should be suspended and execute the suspension, recording its reasoning for human review.

The pressure to automate is coming from the speed of crypto attacks. Flash loan exploits can drain protocols within seconds, and stolen assets can move through multiple addresses, bridges and mixing services within hours. The stakes are measurable: CertiK’s own methodology put crypto losses at 768.4 million USD in September 2026 alone, across 97 incidents, bringing total losses for the year to roughly 2.68 billion USD by the end of September. Its H1 2026 findings logged 1.32 billion USD in losses during the first six months, down 46.8 percent from a year earlier, even as wallet compromises became the largest attack method in the second quarter.

Smart contract security work goes autonomous

Web3 security is one area where CertiK sees autonomous systems taking on tasks that previously required experienced engineers. Smart contract audits have traditionally combined manual code reviews with static analysis, symbolic execution and fuzzing, with human auditors deciding whether tool findings represent genuine vulnerabilities.

Agentic systems can now move through a contract’s call graph, analyze state changes across several contracts and external calls, and hunt for vulnerabilities involving reentrancy, oracle manipulation, access controls and unsafe upgrade mechanisms. CertiK says AI is also being applied to formal verification, with agents generating formal specifications and testing them against contract behavior, reducing the manual burden that used to fall on formal methods engineers.

Human auditors are not disappearing. Their work increasingly centers on verifying AI-generated findings, investigating new economic and game-theoretic attack methods, and checking where automated security systems have blind spots. That matters because previous security research found that audited projects were still compromised through signer devices, administrator keys, backend infrastructure and bridge validators, areas outside the smart contract code itself.

The report extends automated security beyond the audit stage into live monitoring. AI systems can watch pending and confirmed blockchain transactions for flash loan attacks, oracle manipulation and abnormal liquidity withdrawals. In advanced setups, detection can trigger an automated response within the same block window: an agent could pause a vulnerable contract function, activate a circuit breaker or freeze a compromised administrator key without waiting for a human to execute the response.

Tracing stolen funds across chains in real time

Fund tracing is another discipline the report expects autonomous systems to reshape. Investigators traditionally follow stolen assets from address to address through intermediary wallets, mixers, bridges and exchanges, a job that gets harder as funds are split and moved across several blockchains.

CertiK says agentic systems can perform the process continuously, following assets as they move instead of reconstructing the path afterward. Agents can also update address clusters as new activity appears, examining transaction timing, overlapping counterparties and gas fee behavior rather than relying solely on fixed heuristics. Because monitoring tools have historically analyzed individual networks separately, cross-chain laundering has been a structural weakness; agentic systems can combine activity from different chains into a single investigation and keep following funds through bridges and cross-chain swaps.

The report cites laundering connected to the Bybit exploit as an example, pointing to CertiK research that documented the conversion of 86.29 percent of stolen ETH into Bitcoin within one month through mixers, bridges and over-the-counter brokers.

Compliance becomes a real-time machine task

Autonomous systems are simultaneously taking on compliance functions. CertiK says Know Your Address and Know Your Transaction screening can now be performed by AI agents before blockchain transactions settle, letting platforms identify potential exposure to illicit assets in real time rather than after the fact. Regulatory reporting can be automated as well, with agents pulling blockchain data, reconciling it with off-chain records and preparing reports covering obligations such as Travel Rule data sharing and stablecoin reserve attestations.

The workload is growing. A CertiK Skynet report found AML penalties exceeded 900 million USD during the first half of 2025 as jurisdictions shifted from developing crypto frameworks toward active enforcement.

A newer problem emerges when AI agents become blockchain users themselves. Autonomous agents can hold digital assets, execute trades and manage treasuries through DeFi protocols. MetaMask launched an AI Agent Wallet in June that allows autonomous agents to execute swaps, perpetual futures trades and other on-chain transactions under user-established controls. CertiK says organizations may consequently need to audit an agent’s on-chain behavior and preserve records of what information it used, how it reached a decision and what action followed.

The new attack surface

CertiK is careful not to sell automation as a free lunch. Giving AI systems authority to act introduces its own risks. Agentic systems can produce incorrect information while expressing high confidence: an AI-generated suspicious activity report could contain a wrong transaction trail, or an audit agent could wrongly conclude that a formal specification protects against a vulnerability. Human reviewers may become less likely to catch such errors as they gradually trust automated output after seeing it perform well on routine cases.

Attackers also have access to the same capabilities. CertiK warned earlier in 2026 that AI-driven phishing, deepfakes and automated exploit tools were making attacks faster and harder to identify, and the new report says threat actors are already using AI to speed up vulnerability discovery, automate reconnaissance and run more convincing social engineering campaigns. Security agents themselves can become targets, since they may hold permissions over sensitive systems; prompt injection or manipulation of an agent’s inputs could cause autonomous actions such as approving a fraudulent transaction or disabling a legitimate control.

Liability remains unresolved across jurisdictions when autonomous actions cause harm. CertiK says organizations deploying the systems, and the people configuring and supervising them, remain accountable. Its recommendations are concrete: keep complete audit trails of agent inputs, reasoning and actions; set clear limits on decisions agents can make independently; test systems against adversarial manipulation; and assign a named human owner responsible for each agent’s performance and failures.

What it means for the industry

The report’s core message is that the argument is no longer whether AI belongs in crypto security, but who supervises it. Projects that treat autonomous AI as just another software tool, CertiK warns, risk deploying it without adequate audit trails, behavioral monitoring or escalation controls. The firms that get the supervision layer right get faster defense in a landscape where attacks are measured in seconds. The ones that do not may simply be adding a new, confidently wrong participant to their security team.

Source: CertiK Intel3D report via crypto.news, Oct 5, 2026. This article is for informational purposes only and does not constitute investment advice. Digital assets are volatile and carry the risk of loss.

10 thoughts on “CertiK Says Agentic AI Is Joining the Crypto Security Workforce, From Audits to Real-Time Defense”

  1. an AI agent that can suspend your account AND record its reasoning for review? cool until the first false positive freezes someones funds for 48h

    1. thats why the kill switch has to be human gated for anything touching user funds. agent can flag and freeze its own actions, never other peoples money

    2. @auditbeetle the article says humans move to supervision tho. quality control layer is the whole job now apparently

  2. 768 million in losses in september alone and people still wonder why firms are throwing autonomous agents at security. flash loans dont wait for a human to finish their coffee

  3. CertiK calling it an AI security workforce is fitting. The AML and fund tracing parts make sense first since thats where the tedious multi step work lives.

    1. fund tracing is the perfect first job honestly, its deterministic multi hop work. threat response with live privileges is where the liability gets spicy

      1. liability is the word. first agent that freezes a legit bridge hot wallet because a heuristic panicked, that supervision layer gets real popular

  4. The part about audited projects still getting compromised through signer devices and admin keys is the uncomfortable bit. AI agents reviewing Solidity wont catch a leaked key on a laptop.

    1. @Linea exactly, every audit culture bug class they list at the end is off-chain. the agent can pause a contract but it cant stop a brid validator signing garbage

  5. The multi-hop tracing claim I want to see benchmarked. Half of AML work is entity resolution across chains, humans are slow but rarely confident-wrong there.

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,770.00+0.4%ETH$2,711.70+0.4%SOL$120.29-0.4%BNB$787.89-0.2%XRP$1.50+0.0%ADA$0.2683+6.9%DOGE$0.0958+0.4%DOT$1.23+1.8%AVAX$10.96-0.9%LINK$13.95-1.2%UNI$9.17+1.4%ATOM$1.84+4.7%LTC$70.15-1.2%ARB$0.2105+3.1%NEAR$5.20+4.7%FIL$1.17+11.6%SUI$1.22+0.8%BTC$85,770.00+0.4%ETH$2,711.70+0.4%SOL$120.29-0.4%BNB$787.89-0.2%XRP$1.50+0.0%ADA$0.2683+6.9%DOGE$0.0958+0.4%DOT$1.23+1.8%AVAX$10.96-0.9%LINK$13.95-1.2%UNI$9.17+1.4%ATOM$1.84+4.7%LTC$70.15-1.2%ARB$0.2105+3.1%NEAR$5.20+4.7%FIL$1.17+11.6%SUI$1.22+0.8%
Scroll to Top