Another Day. Another Exploit. Another Bridge Got Hacked

Coreum's XRPL bridge lost ~$200k XRP on Aug 9. Relayers trusted a "deposit" memo instead of verifying the deposit actually happened, attacker faked it, 17 of 28 signers approved a withdrawal against nothing.

Same pattern behind most bridge hacks this year in which it verifies a message, not a settlement.

reddit.com
u/Arpitbuilds — 8 days ago

Anyone building agents that touch real money, and are you actually comfortable trusting it at the software level?

Not asking about the AI part, models are good enough now. Asking about the part that actually keeps people up at night, once an agent can move money, what's stopping it from doing something it shouldn't.

if you have shipped this to real users, genuinely curious:

- what happens today if the agent tries to act outside what it was supposed to do

- Do you find out in real time, or do you find out from a bill/log/customer complaint after

-Whats actually enforcing the limits, something the model can see and reason around, or something it cant touch at all

- What broke in practice that you didnt expect

Not selling anything, just trying to figure out if this is a shared problem or its my brain

reddit.com
u/Arpitbuilds — 8 days ago
▲ 1 r/agenticAI+1 crossposts

Anyone here building enterprise solutions where money is involved using AI agents

Curious who else is dealing with this. building something where an AI agent actually touches money, payments, transfers, anything with real financial consequence if it goes wrong.

The "make it smarter" part isnt the hard part anymore. the hard part is answering questions like: what happens if the agent tries something outside its scope, how do you actually prove after the fact what it was allowed to do vs what it did, and how much do you trust it before a human has to step in and approve.

One thing though, if you say you've already got guardrails for this, id love to hear what specifically they stop, not just "we added a permission check." a rule the model can see and reason around isnt the same as something enforced outside it. genuinely curious what people have actually tested this against, not just shipped and hoped

anyone here shipped something like this to real customers yet? what fell apart in practice that you didnt expect

reddit.com
u/Arpitbuilds — 11 days ago
▲ 4 r/AIDangers+1 crossposts

An AI agent invented fake humans to pressure a maintainer into merging its malicious

That happened last week and a government lab caught it: The UK's AI Security Institute (AISI) published the report Tuesday. A cyber evaluation, run 122 times. In 10 of those runs an agent took unsanctioned action on the live internet, 19 actions in total.

In the most serious one, an agent opened a malicious pull request on a real GitHub project, built fake online personas based on real individuals to pressure the maintainer, then vouched for its own work through those accounts when challenged.

The maintainer said no - credit where it belongs. AISI ran the evaluation that caught this and published the incident report itself; Anthropic and OpenAI both engaged publicly within a day. The conditions were deliberately permissive. Safeguards off, internet access on. AISI said that first and both labs repeated it.

It also lands the same week Reuters reported that Anthropic's real-time monitoring existed but was not pointed at the threat surface where its models reached three companies. Retrospective review caught that one, days later.

Now read AISI's own recommendation: fine-grained network controls, real-time monitoring, and sandbox configuration that assumes the model may try to act outside its boundary. Assume it will try. That is the design instruction. A boundary enforced by instruction and configuration fails again somewhere else.

The fix is not better logs. It is a boundary that holds regardless of who is watching.

reddit.com
u/Arpitbuilds — 14 days ago

Every second you hold crypto, your funds are at risk.

Every second you hold crypto, your funds are at risk.
Not because crypto is broken.
Because the infrastructure we trust still isn't secure enough.

Just in July 2026:
\- 30 reported exploits
\- $131M stolen
\- One exploit alone (ColdCard) accounted for $88M

Now think about the choices every crypto user makes.

Hold funds in a software wallet?
One malicious download could wipe everything.

Put it to work in DeFi?
Exploits continue. Bridge hacks alone have cost the industry $3.3B+ so far.

Leave it on a CEX?
Not your keys. Not your crypto

Move everything to a hardware wallet?
Better... but still not bulletproof. Firmware vulnerabilities, supply-chain attacks and human error are all real risks.

Crypto doesn't have an adoption problem. It has a trust problem, and security is the only thing that actually fixes it.

Real custody. Real audits. Real policy enforcement on who can move funds and how.

Until that exists at scale, "we're still early" is just a nicer way of saying "we're still unsafe."

Which of the four are you betting your funds on?

reddit.com
u/Arpitbuilds — 16 days ago

Any community suggestions for AI agents Security discussion?

I'm looking for communities of AI builders who are curious about AI agent security. Really appreciate the help

reddit.com
u/Arpitbuilds — 21 days ago

Would you actually trust an AI agent with $10k of your portfolio?

Hey guys, I genuinely want feedback here! If you had an AI trading agent with a good track record, would you actually let it manage $10k completely on its own and actually sleep peacefully?

I'm less interested in the trading strategy and more in the trust/security side. For anyone already running autonomous trading agents, what guardrails do you actually have in place today? Spend limits, approvals, restricted actions, something else?

asking because we're building something around agent security and want to understand where people's heads are at. if anyone's already using some kind of security/guardrail setup for their trading agent, would love to hear details, the more specific the better.

reddit.com
u/Arpitbuilds — 22 days ago