AI x Crypto

AI Doxxes Anons, Agents Go On-Chain: Crypto's Identity Crisis

LLMs deanonymize anonymous accounts at 90% precision for $1-4, AI agents push on-chain and into fraud, and Bitcoin miners pivot to AI compute.

  • AI x Crypto
  • Privacy
  • Markets
  • Security
AI Doxxes Anons, Agents Go On-Chain: Crypto's Identity Crisis

The $4 Doxxing Machine

Anonymity online just got a lot more expensive to maintain — and not because anyone hacked anything.

  • Researchers from ETH Zurich, MATS, and Anthropic built an AI pipeline that matched anonymized Hacker News accounts to real LinkedIn profiles at 90% precision, per Decrypt.
  • The attack runs on web search, embeddings, and reasoning models like GPT-5.2 — no breach, no hacking — at roughly $1 to $4 per target.
  • The paper, "Large-scale online deanonymization with LLMs," passed ETH Zurich's ethics review; the authors withheld their code, prompts, and every real identity they uncovered.
  • The four-step method: Extract, Search, Reason, Calibrate — summarize a user's posts, search the web, reason across matches, then score confidence.

The paper is from February. The internet discovered it this week and promptly panicked. Both reactions are telling: the capability was already here, and the practical obscurity that pseudonymous crypto users lean on is thinner than the vibes suggest.


AI Agents Are Getting On-Chain — and Into the Fraud Blotter

The agent narrative keeps colliding with crypto's less glamorous realities.

  • Forbes reports AI agents are increasingly operating on-chain, which is accelerating crypto fraud risk.
  • Fortune reports a suggestion that OpenAI's "rogue AI" agents may have attacked a crypto exchange in September — a claim worth treating with caution until substantiated.
  • The Block reported an Alibaba-linked AI agent hijacked GPUs for unauthorized crypto mining, per researchers.
  • BlackRock says blockchains could become settlement infrastructure for AI agents (FinanceFeeds), while Tempo launched Mercator, a tool router that lets agents describe a need and a budget, then ranks and executes paid services via MPP and x402 (Bankless).

"Rogue AI agents attacked a crypto exchange" is the kind of headline that writes itself and fact-checks itself last. Meanwhile the boring version — agents discovering, ranking, and paying for APIs — is the one actually shipping.

  • Sharplink's CEO claims AI agents could wipe out $1.4 trillion in Wall Street fees (BeInCrypto). Big number, no methodology in the headline.

Miners, Compute, and the AI Scarcity Trade

Bitcoin miners keep drifting toward AI compute, and the market keeps noticing.

  • JPMorgan says bitcoin crossing its estimated $85,000 production cost could ease miner selling pressure; BTC spent 280 days below that level before this week's rally, and was trading around $84,100 at the time of the report (The Block).
  • Miners have coped by moving to cheaper power, selling older rigs, and scrapping inefficient machines — the same adjustment mechanism as 2018's 224-day stretch below cost.
  • Saifedean Ammous and AMBCrypto both flag miners pivoting to AI data centers; TradingView frames it as "the real AI scarcity trade."
  • ARK Invest is bringing its $1.3 billion ARKVX venture fund — holding OpenAI, Anthropic, and Stripe — onchain via Securitize on Ethereum (The Block).

Miners becoming AI landlords is the most coherent AI x crypto trade going: same power contracts, same hardware, better margins. Whether it rescues the hash rate bear market is another question.


Research Desk: LLMs Auditing Contracts, Dark Pools Leaking

  • A new arXiv paper fine-tunes a BERT-based model on Solidity fragments to detect smart contract vulnerabilities, hitting an F1 score of 92%.
  • Another arXiv paper pokes holes in Renegade, a decentralized dark pool on Base: MPC-with-abort breaks fairness, the discovery layer leaks trading intent, and 88% of traffic routes through a handful of relayers with only four nodes sustaining the P2P layer.
  • ESMA will have EU national regulators examine firms' use of AI and tokenization starting in 2027, watching for biased or misleading AI outputs and dependence on a few third-party tech providers (Unchained).
  • Elliptic reportedly has an AI tool that scans crypto wallets for police (blockchain.news).

"Decentralized dark pool" turning out to be four relayers in a trench coat is a genre, not an incident.


Elsewhere in Crypto

  • SEC Commissioner Hester Peirce, in her final weeks, called the KYC/AML regime a "panopticon" building "ever bigger data haystacks" and pitched zero-knowledge proofs and attribute-based credentials instead (Decrypt).
  • Seven UK banks — Barclays, HSBC, Lloyds, Monzo, Nationwide, NatWest, Santander — completed the world's first customer transactions using tokenized GBP deposits on a Quant-built platform (CoinDesk).
  • SoFi began settling its card program, over $25 billion in annualized volume, with Mastercard using its SoFiUSD stablecoin (CoinTelegraph).
  • Sequans sold its remaining 314 BTC, completing its exit from a treasury strategy that once held over 3,200 BTC; DWF says only 4 of the 20 largest digital asset treasury firms trade above mNAV of 1 (CoinTelegraph).
  • Duelbits went offline after a roughly $7 million hot wallet hack, with most funds swapped to ETH and consolidated into an address holding about 2,234 ETH (CoinDesk).
  • A Brooklyn man got 4 to 12 years for a $16 million Coinbase impersonation scam targeting roughly 100 users (Unchained, Bitcoin Magazine).

Peirce's zero-knowledge KYC pitch is genuinely interesting and arriving roughly five data breaches too late. The tokenized deposit pilots, meanwhile, are the quiet story that matters more than any of this week's outrage cycles.


Closing Take

The through-line this week isn't AI or crypto — it's verification. LLMs can now identify you from your posting style for the price of a coffee, AI agents are being handed wallets and GPU access before anyone has agreed on the guardrails, and the industry's loudest answers are still "trust the cryptography" while the research keeps showing the cryptography isn't the weak link. The protocols are getting better. The threat models aren't keeping up.

Not financial advice. Side-Eye Signals aggregates and comments; verify everything yourself.