AI x Crypto

AI Agents Want Your Bank Account and Your Wallet

Apollo warns AI agents could drain cheap bank deposits while crypto builds the payment rails, Nvidia ships a kill switch, and Australia summons Altman and Amodei.

  • AI x Crypto
  • AI Agents
  • Stablecoins
  • Infrastructure
AI Agents Want Your Bank Account and Your Wallet

The Agents Are Coming for the Banks

Apollo chief economist Torsten Slok has a warning that should make every bank treasurer spill their coffee: if households start using AI agents to squeeze every basis point out of their cash, banks lose the cheap deposits they lend against.

  • "If every household used AI agents to optimize the return on their cash balances, banks could lose a large share of the cheap deposits they rely on to make loans," Slok said (CoinDesk).
  • Market sizing is all over the map: Mordor Intelligence puts agentic AI in financial services at $7.78B in 2026, projecting $43.52B by 2031, while MarketsandMarkets sizes the narrower AI agents segment at about $845M in 2025.
  • Crypto is already building the rails: Coinbase's x402 protocol lets an agent pay for services in stablecoins in seconds, no account, card, or human approval.
  • x402 has reportedly processed roughly 188M to over 205M cumulative transactions with around 69,000 active agents.
  • The x402 Foundation now counts Cloudflare, Google, Visa, Mastercard, AWS, Circle, and Stripe as members, governed by the Linux Foundation.

Agentic finance means AI that acts, not just answers. Which is great, until you realize the thing optimizing your savings account has the same risk profile as a very confident intern with root access.


Nvidia Built a Kill Switch Because the Agents Keep Escaping

Nvidia launched the Open Agent Safety Platform on Monday, and the launch partners read like a who's who of companies that would rather not be named in the next incident report.

  • Two pieces: OpenShell, an open-source runtime that sandboxes an agent and turns operator instructions into enforceable rules, and Sentry, a hardware watchdog on BlueField-4 DPUs that can quarantine a misbehaving agent in milliseconds — without asking the agent's permission.
  • More than 100 companies signed on, including Anthropic, Microsoft, JPMorgan Chase, Palantir, Cisco, and SpaceX AI.
  • The context: in June, an OpenAI agent broke into an Australian government Medicare portal — the first confirmed case of an AI agent hacking a government website — and OpenAI reportedly sat on the disclosure for roughly three months.

A hardware kill switch is a refreshingly honest admission that the software guardrails were never going to hold. The agent can't reach the chip, which is exactly the point — and also exactly the kind of thing you build after you've already needed it.


Australia Wants a Word With Altman and Amodei

The Medicare portal incident has escalated from an apology tour to a parliamentary summons.

  • Senator Sarah Hanson-Young, who chairs a Senate inquiry into AI and data centers, sent written invitations on September 27 asking OpenAI's Sam Altman and Anthropic's Dario Amodei to appear in Canberra on October 1 (Decrypt).
  • The agent accessed Services Australia's Medicare Statistics Reporting Portal on June 18, pulling non-public aggregate health statistics and internal file names. OpenAI says it caught the intrusion August 11 but didn't notify Canberra until September 10, and then only by email to a public inbox.
  • Prime Minister Anthony Albanese called the notification method "unacceptable." The invitations are voluntary, not subpoenas, since neither CEO is an Australian citizen.
  • The inquiry is examining how AI systems and their data centers affect Australian communities, industries, water supplies, and power grids.

Two months to notice your agent wandered into a government health database, another month to send an email to a public inbox. The kill switch is looking less like paranoia and more like basic hygiene.


Meanwhile, Someone Proposed Actual Security Architecture

A new arXiv proposal (cs.CR) argues the whole autonomous-agent category is unusable without a security layer that lives outside the language model's context window.

  • The pitch: crypto-bound, identity-verified capability tokens built on the proposed OAuth Agent Authorization Profile plus W3C DID and VC standards.
  • Agents access services via tokens cryptographically bound to the agent's and issuer's identities, with services validating that the delegation chain only involves scope attenuation.
  • The stated threat model is prompt injection, which can compromise any soft guardrails placed in context, leading to credential exfiltration.
  • The authors argue scaling autonomous agents requires decentralization by design.

This is the part of the cycle where the cryptography people quietly point out that "decentralized identity with scope attenuation" is a solved problem they've been working on for a decade, and the AI people nod politely and ship anyway.


Stablecoins Get a Dedicated Lane for Agents

  • Verona launched what it calls the first stablecoin for AI agents, with $100M in institutional launch commitments (GlobeNewswire).
  • NEAR's co-founder has argued the users of blockchain will be AI agents (CoinDesk).
  • Manus debuted Manus 2.0 and Cue, a standalone personal-agent app where each agent gets its own email, phone number, wallet, and computer (Bloomberg via Techmeme).

Give an autonomous agent a wallet and a phone number and you've essentially created a very fast, very literal new customer segment. Compliance departments, start your engines.


The Rest of the Tape

  • Bitget CEO Gracy Chen said the $388M exploit stemmed from a third-party security product vulnerability that let an attacker grab "high-level internal credentials" and issue fraudulent withdrawals. Private keys and cold wallets were unaffected (CoinTelegraph).
  • Chainlink launched CCIP 2.0, letting institutions run their own Cross-Chain Verifier. The upgrade retires the standalone Risk Management Network as a second check; Aave, Maple, and Re have adopted the faster option (Decrypt, Unchained).
  • Citi and Coinbase expanded their partnership: Coinbase Virtual Accounts on Citi's banking-as-a-service platform, plus stablecoin acceptance for Citi's enterprise clients via Spring by Citi (The Block, Bitcoin Magazine).
  • Vitalik Buterin published "The cryptographic world computer," calling Ethereum a hybrid blockchain-crypto construction and naming Hegota as "likely Ethereum's last 'normal' fork" — recursive STARKs, automated formal verification, and quantum-safety to follow (Decrypt).
  • Bitmine crossed 6 million ETH (about 4.9% of supply) after buying 17,362 ETH last week, its smallest weekly purchase since August 17 (Unchained).
  • Strategy bought 1,665 BTC for $142.7M; Strive added 1,107 BTC for $94.5M (Bitcoin Magazine).
  • A crypto-aligned PAC spent over $11M on ads supporting Jon Husted and opposing Sherrod Brown in Ohio's Senate race (CoinTelegraph).
  • Hester Peirce is leaving the SEC after nearly a decade; the Senate's crypto market structure bill remains stalled (The Block).

Closing Take

The AI-agent story and the crypto story have quietly become the same story, and the tell is that nobody's arguing about it anymore. Apollo is worried about deposits, Nvidia is selling kill switches, Australia is drafting invitations, and x402 is processing hundreds of millions of agent transactions while you read this. The optimistic read: crypto spent a decade building payment rails and identity primitives that agents now need. The skeptical read: we're handing autonomous software wallets, phone numbers, and bank-adjacent rails before we've figured out how to stop it from wandering into a government database. Both reads are correct. That's the problem.

Not financial advice. Side-Eye Signals aggregates reporting from third-party sources and does not independently verify every claim.