A joint security report by SlowMist and Bitget warns of significant security risks associated with the use of AI agents in Web3 environments. The report, released recently, focuses on vulnerabilities that could compromise user assets and protocol integrity as AI agents become more prevalent in decentralized application development and on-chain operations.
Key Findings: AI Agents May Leak Sensitive Configuration Data
During automated development processes, AI agents often require access to configuration files for debugging, log analysis, or dependency installation. Without clear ignore strategies or robust access controls, sensitive information such as private keys, API keys, and database credentials could be logged, sent to remote APIs, or exposed by malicious plugins. The report emphasizes that unlike traditional software systems, many operations in Web3—including on-chain transfers, token swaps, liquidity additions, and smart contract calls—are irreversible. Once a transaction is signed and broadcasted, it is extremely difficult to reverse or roll back. This irreversibility amplifies the security risks when AI agents handle on-chain actions, demanding heightened vigilance and stronger protective measures.
Irreversible Operations Amplify Risks: No “Undo” in Web3
The report stresses that common error recovery methods in traditional internet applications—such as database rollbacks or request cancellations—are largely unavailable in Web3. If an AI agent executes an incorrect on-chain operation due to misconfiguration or attack, users face direct asset losses that are nearly impossible to recover. For example, an AI agent could be tricked into executing unintended token transfers or interacting with malicious contracts, resulting in fund theft. Furthermore, the AI agent itself can become an attack vector: adversaries may poison training data, implant backdoors, or exploit plugin vulnerabilities to indirectly control the agent’s behavior.
Industry Implications and Recommendations
SlowMist and Bitget urge developers and users to implement stricter security measures for AI agents, including: applying the principle of least privilege and whitelisting files and APIs accessible to AI agents; introducing manual review or two-factor confirmation before on-chain operations; conducting regular audits of AI agent code and dependencies; and using sandbox environments to isolate agent runtime permissions. The report also advises Web3 projects to carefully consider security boundaries when integrating AI functions, avoiding directly granting critical private keys or signing authority to agents.
As AI technology accelerates its integration into the crypto industry, this joint report serves as a timely reminder: in the pursuit of efficiency, security must remain paramount—especially in the irreversible world of Web3. Users should also exercise caution and be prudent when authorizing AI agents to perform any on-chain actions.

