Agentic AI is becoming part of the crypto security workforce: Certik
by Rony Roy, Rony Roy · crypto.newsAgentic AI has started taking over work once handled directly by human analysts across cybersecurity, anti money laundering and compliance, with autonomous systems now investigating threats, tracing funds and acting on security incidents with limited human intervention.
Summary
- Agentic AI is moving beyond flagging suspicious activity, with autonomous systems increasingly able to investigate threats, trace funds and act on security incidents with limited human involvement.
- CertiK sees AI agents taking on smart contract analysis, live transaction monitoring and cross chain fund tracing as crypto attacks become faster and more complex.
- Compliance work could increasingly be handled by AI agents that screen addresses and transactions in real time and prepare regulatory reports using onchain and offchain data.
- Greater autonomy creates new risks, including incorrect decisions, prompt injection and manipulation of agents that have permission to interact with sensitive systems.
- CertiK said responsibility remains with organizations and human supervisors, making audit trails, authority limits and clear escalation procedures necessary as AI agents take on more security work.
According to a new CertiK Intel3D report, the change goes beyond using artificial intelligence to flag suspicious activity or summarize information for analysts. Agentic systems can reason through multiple steps, call external tools and APIs, collect evidence, take actions in live environments and assess the results before deciding what to do next.
CertiK describes the emerging model as an AI security workforce, where autonomous systems operate within defined roles while human experts move toward supervision, quality control and accountability.
Agentic AI is moving from security assistant to operator
For much of the past decade, AI used in cybersecurity and compliance played a supporting role. Machine learning systems could identify anomalies, while natural language tools helped summarize alerts or prepare reports that were ultimately reviewed and acted upon by people.
Agentic AI changes how much of that process can happen without direct human involvement.
In a security operations center, CertiK said an autonomous system could investigate an unusual login, retrieve the device fingerprint and location history, compare the information against threat intelligence, decide whether an account should be suspended and execute the suspension. Its reasoning could then be recorded for human review.
The report argues that such systems should increasingly be treated as workforce participants with defined responsibilities instead of conventional software tools.
Responsibility, however, remains with people and organizations. CertiK said AI systems do not hold legal or operational accountability, leaving the organizations deploying them and the humans configuring and supervising their work responsible for the outcome.
Under that model, an AI agent needs a defined scope of authority, escalation procedures and a human owner. CertiK said organizations that view autonomous AI as another software tool risk deploying it without adequate audit trails, behavioral monitoring or escalation controls.
The pressure to automate security work is partly coming from the speed of crypto attacks. Flash loan exploits can drain protocols within seconds, while stolen assets can move through multiple addresses, bridges and mixing services within hours.
Security losses remain substantial. As crypto.news previously reported, crypto losses reached $768.4 million in September under CertiK’s methodology, across 97 incidents. The firm’s figures placed total losses during 2026 at roughly $2.68 billion by the end of September.
AI agents are taking on smart contract security work
Web3 security is one area where CertiK sees autonomous systems taking on tasks that previously required experienced engineers.
Smart contract audits have traditionally combined manual code reviews with static analysis, symbolic execution and fuzzing tools. Those systems could surface potential vulnerabilities, but human auditors generally had to determine whether the findings represented genuine security problems.
Agentic systems can now move through a contract’s call graph, analyze state changes across several contracts and external calls, and look for vulnerabilities involving reentrancy, oracle manipulation, access controls and unsafe upgrade mechanisms.
CertiK said AI is being applied to formal verification as well. Agents can generate formal specifications and test them against contract behavior, reducing some of the manual work previously required from formal methods engineers.
Human auditors still remain part of the process. Their work increasingly centers on verifying findings generated by AI, investigating new economic or game theoretic attack methods and checking where automated security systems themselves may have blind spots.
Conventional audits have faced growing scrutiny as attacks move beyond vulnerabilities contained directly in smart contract code. Previous security research found that projects which had completed audits were still compromised through areas including signer devices, administrator keys, backend infrastructure and bridge validators.
CertiK’s report extends automated security beyond the audit stage into live transaction monitoring. AI systems can watch pending and confirmed blockchain transactions for flash loan attacks, oracle manipulation, abnormal liquidity withdrawals and other exploit patterns.
In more advanced setups, detection can trigger an automated response within the same block window. An agent could pause a vulnerable contract function, activate a circuit breaker or freeze a compromised administrator key without waiting for a person to manually execute the response.
AI could trace stolen crypto across chains in real time
Fund tracing is another part of Web3 security where the report sees a growing role for autonomous systems.
Investigators traditionally follow stolen assets from one address to another, tracking how funds pass through intermediary wallets, mixers, bridges and exchanges. The work becomes more difficult as assets are split into smaller amounts and moved across several blockchains.
CertiK said agentic systems can perform the process continuously, following assets as they move instead of reconstructing their path only after transactions have already occurred.
AI systems can similarly update address clusters as new blockchain activity appears. Instead of relying solely on fixed heuristics, agents can examine transaction timing, overlapping counterparties and gas fee behavior to determine whether several addresses are likely controlled by the same entity.
Cross chain laundering creates another problem because monitoring tools have historically analyzed individual networks separately. Agentic systems can combine activity from different chains into a single investigation and continue following funds as assets pass through bridges or cross chain swaps.
The report cited laundering connected to the Bybit exploit as an example, saying previous CertiK research documented the conversion of 86.29% of stolen ETH into Bitcoin within one month through mixers, bridges and over the counter brokers.
CertiK has previously warned that attackers are changing their methods even when headline losses decline. Its H1 2026 security findings put crypto losses at $1.32 billion during the first six months of the year, down 46.8% from a year earlier, while wallet compromises became the largest attack method during the second quarter.
AI agents create a new compliance problem
Autonomous systems are taking on compliance functions at the same time.
CertiK said Know Your Address and Know Your Transaction screening can now be performed by AI agents before blockchain transactions settle. Agents assess the risk associated with an address or transaction in real time, allowing platforms to identify potential exposure to illicit assets before completing a transfer.
Regulatory reporting can be automated as well. Agentic systems can pull blockchain information, reconcile it with offchain records and prepare reports involving obligations such as Travel Rule data sharing and stablecoin reserve attestations.
The regulatory workload facing crypto companies has already grown. An earlier CertiK Skynet report found that AML penalties exceeded $900 million during the first half of 2025 as jurisdictions moved from developing crypto frameworks toward active enforcement.
A separate problem emerges when AI agents become blockchain users themselves.
Autonomous agents can hold digital assets, execute trades, manage treasury operations and interact with decentralized finance protocols. CertiK said organizations may consequently need to audit an agent’s onchain behavior and preserve records showing what information it used, how it reached a decision and what action followed.
The scenario is no longer limited to research. MetaMask launched an AI Agent Wallet in June that allows autonomous agents to execute swaps, perpetual futures trades and other onchain transactions under controls established by users.
CertiK warns autonomous security creates its own attack surface
Giving AI systems authority to act introduces another set of security risks, according to the report.
Agentic systems can produce incorrect information while expressing high confidence. In AML work, an AI generated Suspicious Activity Report could contain an incorrect transaction trail. During a smart contract audit, an agent could incorrectly conclude that a formal specification protects against a vulnerability.
Human reviewers could become less likely to catch such errors if they gradually place more trust in automated output after seeing the system perform well on routine cases.
Attackers have access to many of the same capabilities. CertiK said threat actors are already using AI to speed up vulnerability discovery, automate reconnaissance and create more convincing social engineering campaigns.
The company warned earlier in 2026 that AI driven phishing, deepfakes and automated exploit tools were making attacks faster and harder to identify.
Security agents themselves could become targets because they may have permission to interact with sensitive systems. CertiK said prompt injection or manipulation of an agent’s inputs could potentially cause autonomous actions such as approving a fraudulent transaction or disabling a legitimate security control.
Liability remains unresolved across jurisdictions when autonomous actions cause harm, according to the report. CertiK said organizations deploying the systems and the people responsible for configuring and supervising them remain accountable, requiring records of an agent’s authority, escalation thresholds and any human approval involved before consequential actions are taken.
The firm recommends keeping complete audit trails of agent inputs, reasoning and actions, setting clear limits on decisions agents can make independently, testing systems against adversarial manipulation and assigning a named human owner responsible for each agent’s performance and failures.