The Main Event: Ethereum's Agent Swarm Has a Cult and a Chart
Bankless digs into IMD (identity.md), an Ethereum project whose stated goal is a community-owned company run entirely by AI agents. The machinery is genuinely odd, which is presumably the point.
- 2,000 NFTs that function as work permits, not PFPs
- A swarm of agents that holders run on their own machines
- A Uniswap V4 hook that burns $IMD on sells
- A launchpad where new coins are priced in $IMD
Per Bankless, the agent network opened to holders on Sept. 20 with a couple dozen agents online. Five days later it's at +370 agents, and $IMD is up ~200% over the past week.
- $IMD price: ~$9.73
- Supply: ~7.1M (down from 10M)
- Market cap: ~$69M
- Staked as sIMD: ~2.3M
- NFT floor: 1.99 ETH (~$5,360)
- Unique NFT owners: ~780
- Seats enrolled in the swarm: 380 of 2,000
- Accepted work submissions: +43,800
- AI inference tokens consumed to date: ~17.3B
IMD comes from Adam (@surfcoderepeat), the dev behind the onchain Tamagotchi game Fren Pet, which launched on Base in August 2023 and — credit where due — still runs. The token lineage is $FP → $VIBE (Oct. 2025 bridge to Ethereum) → $IMD (May 2026, alongside the free NFT mint).
The bull case is that the swarm becomes a workforce other protocols pay — reasoning oracles and the like. The bear case is that 380 of 2,000 seats filled and a 200% weekly candle is a cult, not a company. Both can be true. "Community-owned company run entirely by AI agents" is a mission statement, not a revenue line.
BlackRock Wants You to Know Agents Need Money Rails
BlackRock is out with the thesis that AI agents will create a new economy for stablecoins, blockchain, and compute (Business Today, The Coin Republic, The Cryptonomist). The framing: machine-native money for machine-native buyers.
Coinbase's CEO is already on record saying crypto and stablecoins will become the go-to payment method for AI agents (Tekedia). Raoul Pal backed the BlackRock tokenization thesis while insisting it "doesn't go far enough" — his line being that everything will be a token (Yahoo Finance).
Separately, Polymarket partnered with OpenWorlds on AI trading agents (Crypto News), which is either the future of markets or the fastest way to automate your own liquidation.
"AI agents will drive digital asset demand" is a great slide. It is also the kind of slide that gets written before anyone has to reconcile an agent's spending limit with a smart contract that has none. Note who's selling the picks-and-shovels version of this story versus who's buying.
Meanwhile, the Security Desk Is on Fire
Bitget confirmed attackers moved roughly $387.5M–$388M off the exchange Thursday, revised up from an initial $351.6M after counting Zcash and TRON transfers (Unchained, Bitcoin Magazine, CoinDesk).
- No private keys were needed. CEO Gracy Chen said the attacker compromised a backend wallet system, spoofed transaction data, and triggered the authorization process — Bitget's own systems signed the transfers.
- Chen attributed the method to DPRK-linked groups based on IP behavior and on-chain signatures.
- Mandiant and SlowMist are investigating. Withdrawals were suspended; a status update was promised by midnight ET.
- Nansen traced funds to
68,300 ETH ($184M) across eight wallets, none of which had sent a transaction as of Friday evening.
The playbook echoes the $1.5B Bybit theft of Feb. 2025. Onchain analyst Specter linked stolen XRP to July's $24M AFX hack, attributed to TraderTraitor. Bitcoin Magazine notes experts say AI tooling is letting cyber crooks work faster.
Separately, Payy ruled out a compromised key in a $1.92M drain of users' non-custodial deposits, saying its bridge was exploited via verifyRollup calls and that it's checking findings with an audit firm (Unchained). And Magic Eden warned that NFTs listed on its now-closed EVM marketplace between Feb–Oct 2024 may be exposed to a Limit Break Payment Processor V2 exploit; a whitehat operation rescued 23,155 NFTs worth $5.7M+, but 660 WETH wasn't recovered (Decrypt).
Two of these are "revoke your approvals" stories and one is "your exchange's backend got socially engineered at the infrastructure layer." The common thread: the approvals and the plumbing are where the money leaks, not the cryptography.
Research Corner: Agents Are Getting Governed (Slowly)
Two new arXiv papers worth a skim:
- skilder (cs.AI) packages agent capabilities into roles — bundles of skills, tools, instructions, and the limits that bound them — served through a single MCP server so tool scope is enforced deterministically rather than by prompt vibes. Across 13 tasks and six models, the simulated authorization layer logged no unauthorized tool call or parameter violation.
- Decision Hijacking (cs.CR) tests prompt injection against Jev, a non-generative decision model with schema-defined outputs, across 510 reconstructed InjecAgent cases. Malicious content shifted action probabilities but rarely flipped the target; adaptive attacks using score feedback doubled mean attacker-target probability and raised fresh-validation success from 1.8% to 3.5%.
On the tooling side, Hugging Face detailed upgrades from the gpt-oss release — MXFP4 quantization, zero-build kernels, a new chat format — that should benefit other models in transformers (HF Blog). And Together AI now lets you fine-tune any compatible Hub model on its infrastructure (HF Blog).
"Schema-defined outputs change but do not eliminate prompt-injection risk" is the most honest sentence in AI security this week. If your agent has a spending limit, the limit is a suggestion until something other than a prompt enforces it.
Also Worth Knowing
- Australia's PM Anthony Albanese told the UN that an OpenAI agent breached a government website — a Medicare statistics portal in June — and said OpenAI didn't notify the government until Sept. 10 (CoinTelegraph).
- FET surged 3.09% amid a broad crypto rebound and renewed AI narrative (CoinMarketCap).
- Crypto's Washington bench thins: Blockchain Association CEO Summer Mersinger exits Oct. 16, with Kristin Smith returning as interim; SEC Commissioner Hester Peirce resigns effective Oct. 2, leaving the agency with two commissioners (Unchained, CoinDesk). Both exits land 10 days after the Senate blocked the Clarity Act.
- SEC staff said token buybacks on functional networks don't constitute a promise of managerial effort — but warned they might on unfinished ones (Unchained).
- OG.com filed with the CFTC to list single-stock perpetual futures, joining Coinbase, Kraken's Bitnomial, and Kalshi (CoinTelegraph).
- CoinMarketCap acquired CoinGlass for derivatives data across 28 exchanges and 2,500+ instruments (CoinTelegraph).
- Strategy proposed daily dividend accrual on STRF, STRC, STRK, and STRD — 365 record dates a year instead of 24 (Decrypt).
- Bitcoin slipped
0.9% to **$83,600** after a $15.6B Deribit options expiry; XRP and Solana outperformed on the week (Decrypt).
Closing Take
The AI x crypto trade this week has two faces. One is IMD's swarm — 380 agents doing real inference work, 17.3B tokens burned, and a token up 200% on the strength of a story about what the swarm could be paid for. The other is BlackRock telling institutions that agents will need stablecoins and compute, which is a much bigger claim with much less on-chain evidence so far. Somewhere between the cult and the thesis sits the actual question: who pays the agents, for what, and can anyone stop one from signing a bad transfer? Bitget just answered the last part for $388 million.
Not financial advice. Do your own research; the swarm is not your fiduciary.
