CertiK Intel3D report says AI agents can trace stolen crypto, humans stay accountable

Editorial illustration: Three transparent network panels share a glowing amber path. A small robot sits on the middle panel, while a person's hand grips a lever connected to a red-lit gate on the right.

In brief

  • CertiK's Intel3D report says AI agents can trace stolen crypto across chains and pause contracts.
  • Crypto attacks now move faster than human analysts can respond, the report argues.
  • Bybit example: CertiK says 86.29% of stolen ETH was converted to Bitcoin within a month.
  • Each AI agent needs a human owner accountable for its decisions, according to the report.

Speed is the argument

CertiK's case rests on one claim: crypto attacks now move faster than human analysts can respond. The Intel3D report centers on agentic AI (software that acts on its own rather than waiting for a prompt), and it argues those agents can monitor on-chain transactions continuously. When they spot a threat, the report says, they can trigger defensive responses, including pausing a vulnerable contract within the same block window.

CertiK frames that as essential against attacks like flash loans.

The firm said manual tracing struggles to keep pace with laundering routes that run through mixers and bridges. According to the report, the agents can also prepare regulatory reports and activate circuit breakers.

The hacks CertiK points to

CertiK cited the Bybit exploit, saying 86.29% of the stolen ETH was converted to Bitcoin within a month. The report also referenced major breaches at Bitget and Liquid Network in September 2026. CertiK uses those incidents to argue that the response window after a hack is short.

It doesn't name specific crypto tokens using these AI capabilities.

Who answers when the agent gets it wrong

This is where the report gets more careful. CertiK is explicit that agents should operate within defined roles and set authority levels, and that organizations must assign a human owner to each agent who's accountable for its decisions.

The report names specific failure modes: an agent freezing a legitimate transaction, or filing an inaccurate report. To limit that risk, CertiK recommends detailed audit trails and rigorous testing. It also wants autonomy capped. That cap is meant to address plain errors as well as adversarial attacks, where bad actors try to trick the AI itself.

CertiK argues agentic AI improves operations in both Web2 and Web3 settings. It's a bullish read on automation, but the report stops short of handing the agents full control (a named human still owns each one's decisions).

Frequently asked questions

What does CertiK say AI agents can do in crypto security?

According to CertiK's Intel3D report, autonomous AI agents can trace stolen crypto across chains, write suspicious activity reports and pause vulnerable smart contracts. The report says they can also prepare regulatory reports and activate circuit breakers.

Why does CertiK argue AI agents are needed after hacks?

CertiK's report argues crypto attacks now move faster than human analysts can respond and that manual tracing struggles to keep pace with laundering routes through mixers and bridges. It cited the Bybit exploit, saying 86.29% of the stolen ETH was converted to Bitcoin within a month.

Who is responsible when a CertiK-style AI agent makes a mistake?

CertiK says organizations must assign a human owner to each agent, and that person is accountable for its decisions. The report names failure modes such as freezing a legitimate transaction or filing an inaccurate report, and recommends audit trails, rigorous testing and capped autonomy.