On Oct. 7 at TOKEN2049 in Singapore, Dragonfly managing partner Haseeb Qureshi delivered a talk titled Agents + Crypto: What's Real & What's Cope. In the version of the speech published after the event, he opened with a blunt correction of his own earlier view: he had argued that agents would use crypto and that traditional financial rails would not be ready before those agents came online. He said that view was wrong.
His revised thesis was simple: agents may not need crypto, but people do.
The early-year agent payment story, in his view, did not hold up
Qureshi said one of the dominant market narratives earlier this year was that agentic payments were about to break out, with a common claim that crypto’s real users would not be ordinary humans but AI systems.
He said that narrative lost traction after November last year. In his telling, agents have not adopted x402 at scale, referring to Coinbase’s agent payment protocol, and 90% of payment volume on x402 has come from farming activity.
At the same time, he argued that agents are already here in practical terms. Consumer-facing agent products are growing quickly, and OpenAI is also building in the category. But when those agents actually pay for things, he said, they are mostly using cards and credit cards rather than crypto rails.
Cards, not tokens, are handling most current agent commerce
Qureshi named Rain, Visa, Ramp and Stripe as companies that have already launched agentic card products. These products can generate subordinate cards under a user’s main card, with spending caps and merchant or category restrictions.
His point was that those firms have recognized agentic commerce as a meaningful opportunity and are already prepared for it.
He also used his own experience as an example. He said he has given an agent a crypto wallet, but that setup still limits what the agent can buy today. He also gave the same agent a card, and most of the items the agent purchased ended up being paid for with the card.
From that, he drew a narrow but clear conclusion about the current consumer environment: cards are basically the answer right now. He did not present cards as a universal solution. He said they are common in developed markets such as the United States, but not everywhere, while agents will be everywhere. So cards are not the only answer. Still, he said the claim that agents would use crypto while traditional rails were unprepared has already been overtaken by events, because those rails are ready.
That was the “cope” side of the story in his framing. Outside standard crypto use cases such as international payments and large transfers, he said the overlap between agents and crypto is smaller than the market narrative suggested. The things agents may do with crypto are, in his view, largely the same things people already do with crypto today.
Where agents matter more: they make hard systems easy to use
For Qureshi, the more important point is that agents make difficult tasks easier. He said governments around the world are already feeling the pressure from that shift.
He described many public services as systems built on bureaucratic friction: filing lawsuits, submitting complaints to the Consumer Financial Protection Bureau, applying for benefits, or filing housing complaints. The systems work in part because many people never make it through the process.
That is changing, he said. Across countries, application volumes in these categories are surging as AI agents faithfully act on behalf of users and consume public-service capacity. His argument was that governments were never designed for a world where everyone can file every complaint with ease. In practice, these systems relied on a hidden rationing mechanism, where difficulty and inconvenience throttled demand. In the age of agents, that mechanism stops working.
He expects agents to make crypto more dependable for users
Qureshi applied the same logic to crypto itself. Crypto remains hard for ordinary users, he said. Many do not know how to use wallets, manage gas fees, or deal with bridges, so they avoid the system. And users are not only hesitant. They also make expensive mistakes, including hacks, phishing incidents and honeypots. He said onchain records show that a meaningful share of assets has been permanently lost through errors of that kind.
That is why he sees one of the biggest effects of agents not in payments, but in reliability. His phrasing was that agents can protect users from their own stupidity.
He compared that function to banking. Even after more than a decade in crypto, he said, sending a large sum from a wallet still makes him nervous because of the possibility of making a catastrophic mistake. By contrast, he does not feel the same when moving money through a bank account, because the bank acts as a layer that catches obvious errors. In his framing, the bank is an intelligent intermediary between the user and the money.
He argued that once AI becomes the API for accessing crypto, something similar can exist onchain. An agent could screen for phishing, detect spoofed interfaces caused by DNS poisoning, review conditions before interacting with a compromised contract, and verify whether a copied address belongs to the intended recipient.
His case for agents here was operational rather than ideological. Agents do not get lazy, skip steps or get tired, he said, and they do not make the routine errors that humans make. On that basis, he said the way people use crypto five years from now will not look like the way they use it today, and trust in crypto will be rebuilt on different terms.
Privacy, he argued, was often protected by friction rather than by law
The second half of the talk shifted to privacy. Qureshi said privacy has never really been secured simply because it is a right. In practice, he argued, privacy often survived because surveillance and tracking were expensive and difficult.
He cited a U.S. Supreme Court justice in a GPS tracking case as saying that, in the pre-computer era, the strongest protection for privacy was practical rather than constitutional or statutory. The key limit was not always law. It was that police did not have the time or resources to follow every suspect around the clock.
He said technology has changed that balance. He also referred to comments from Anthropic founder Dario Amodei during clashes with the U.S. Department of Defense, arguing that powerful AI makes it possible to automatically assemble a complete picture of a person’s life at scale. Data on nearly everyone has already leaked and scattered across the internet, he said. What used to prevent anyone from reconstructing who you are and what you are doing was largely cost.
Qureshi pointed to the controversy around the U.S. camera company Flock as a concrete example. Cameras at street corners are not new, and their presence is not inherently illegal. The difference is scale. If every corner has cameras and AI can search all footage instantly, a quantitative change becomes a qualitative one. In that setting, government can effectively know where everyone is all the time.
He said crypto holders are seeing a related shift. Physical attacks targeting crypto holders rose sharply in 2025 and 2026, according to his account, with reported incidents hitting record highs. For people whose holdings are publicly traceable, the old assumption that no one would spend the effort targeting them no longer offers much comfort. The cost of finding and profiling targets is falling.
AI strengthens the state; crypto gives individuals a counterweight
That is where crypto matters most to him. Qureshi said this emerging panopticon is a major reason crypto exists at all. In his framing, AI and crypto push in opposite directions. AI expands state power by removing old limits: slowness, weak reasoning and the inability to make sense of large volumes of data. Crypto does the reverse. It shifts some power away from the state and back to individuals.
He argued that in a world where governments are getting stronger and more capable of seeing everything, crypto may be the only real hedge available to individuals.
Still, he acknowledged a stubborn pattern in privacy history: people say they care about privacy, but they only adopt privacy tools when those tools become easy to use. Importance alone does not drive adoption.
He used several examples. Encrypted web traffic only became the norm after Let’s Encrypt made HTTPS certificates close to free, he said. Before that, SSL was slower and more expensive, and was often limited to checkout pages. Messaging followed a similar path: billions of people only began using encrypted messaging once products such as Signal became usable and WhatsApp rolled out end-to-end encryption at scale. He said Zcash is now showing the same pattern, with improvements in user experience directly explaining growth in shielded-address usage.
Agents could become the user’s privacy operator
His main prediction was that AI could drive the same transition in privacy. A user’s own AI agent, he said, could become a direct defense against privacy intrusion.
He described a future in which a user simply tells the agent to make them invisible. The agent could then remove public traces, tighten operational security, work to delete information from the dark web, and model how an attacker would try to find and target that person.
That is where privacy protocols such as Zcash fit in for him. He said these systems are still hard to use today. But if agents become the interface through which users access crypto, that complexity can disappear from the user’s side. The agent would decide when not to use Bitcoin, when to use Zcash, and when plaintext should be replaced with encrypted text.
Private AI was his final piece of the picture
Qureshi ended by naming private AI as the last missing piece. He used the privacy-focused AI platform Venice, a Dragonfly portfolio company, as his example. He described it as a private version of ChatGPT built on crypto rails. Users, he said, can even use it anonymously by registering with an Ethereum address and paying with stablecoins.
He said one of the central civil-liberties battles of the next decade will be how individuals protect themselves from the continued expansion of state power. A second battle will be how society keeps control over AI itself, which he described as the most politicized technology of the coming decade.
His conclusion returned to the opening correction
Qureshi closed by rejecting the idea that agents will use crypto for everything they do. For most consumers, he said, agents will probably use the same tools people already use.
But that does not reduce crypto’s importance in his argument. It increases it. In a world where AI strengthens state capacity and strips away the friction that once protected privacy, crypto becomes more important as protection for the individual. His final line returned to the point he opened with: your agent may not need crypto. You do.

