Our cryptos already face many threats: hacks, bugs, phishing, human errors. But a new flaw is gaining momentum. Artificial intelligence agents, supposed to assist us, could become our worst enemies. A Slowmist study reveals that flaws in MCP protocols expose portfolios to invisible attacks. Behind their lines of code, these AI assistants could execute the orders … of an attacker.

In short
- Crypto agents use MCP, a protocol as flexible as it is vulnerable to targeted attacks.
- Malventy plugins make it possible to divert the AI agents to steal keys and crypto backgrounds.
- Slowmist identified four major attack vectors through an educational project called MasterMCP.
- Secure plugins, behaviors and privileges must become the absolute priority of Crypto developers.
When AI becomes the fault: the emergence of a new threat
Artificial intelligence invites itself into the crypto at high speed. At the end of 2024, more than 10,000 crypto agents were active. By the end of 2025, this figure should exceed one million. These AI agents, considered a revolution in the sector, are not models like GPT-4, but real -time connected extensions to walletsbots or dapps.
Their mission? Make automated decisions and run onchain actions. All from a central protocol: the Model Context Protocol (MCP).


The problem is that this flexibility also makes its weakness. MCP acts as the brain of these agents. He decides which tools to use, which functions to execute, how to respond. According to Slowmist, this architecture opens an attack surface ” Uncontrollable without strict sandboxing ». Of the malicious plugins An agent may divert, inject toxic data or get it to call trapped external functions.
The Safety Expert Monster Z specifies:
The poisoning of agents and MCP results from malicious information introduced during the interaction phase.
Clearly, even a well -trained agent can betray if he receives a toxic instruction at the wrong time. Worse: according to him, this threat goes beyond the poisoning of classic AI models in terms of gravity.
A crypto system that can be self -destructing from the inside
The attacks are diverse, precise and devious. Slowmist documents four main ones in his report. The MasterMCP project reproduces them, to help developers understand the danger.
The first, the Data Poisoning, uses plugins like “Banana” to have absurd tasks carried out or divert the user. Afterwards, JSON injection allows you to bypass security by calling malicious data locally. The substitution of functions, via orders such as “Remove _Server”, replaces critical operations with obfuscated code.
Finally, The Inter-MCP call encourages an agent to interact with unsecured servers To widen the fault.
All of these attacks start from unbeknop plugins. However in the crypto world, any plugin connected to a wallet is a gate. Guy Itzhaki, CEO of Fhenix, sums up well:
Opening your system to third -party plugins is opening a breach out of your control.
Behind a simple AI assistant hides a risk of leakting private keys, flights, manipulation of orders. And as Lisa Loud, director of Secret Foundation points out: ” It is in beta versions that we most often get hacker. »»
Referring to security to later, is to expose users to invisible but potentially catastrophic attacks.
What to do? Secure AI before it eats our cryptos
Faced with this threat, the reaction should not be panic, but prevention. Slowmist recommends a set of accessible but demanding technical measures. It's necessary Check each plugin, limit privileges, isolate environments and continuously analyze the behavior of agents. These measures must be native, integrated from the first line of code.
Here are some figures that show why we must act now:
- 1 million Crypto agents expected at the end of 2025, According to Vaneck ;
- 4 types of MCP attacks already tested by experts (Data Poisoning, JSON, OVERRIDE, CROSS-CALL) ;.
- The MasterMCP project proves that these attacks can be simulated with a few lines of Python;
- A single MCP flaw can cause private keys to Slowmist;
- Less than 10 % of the Audité crypto projects use an isolated environment or a sandbox.
Developers must also train their teams, educate their users and document the expected behavior. It's not about stopping using AI, but not save security. Better a slightly slow system than a empty portfolio.
While agents threaten our cryptos, another concern rises among financial giants. Can Blackrock wonders: can Bitcoin survive in the quantum era? Because if AI can deceive a plugin, a quantum computer could decipher our private keys. And there, more blockchain, no more wallet: just data stolen in silence. The crypto revolution will also have to survive that of physics.
Maximize your Cointribne experience with our 'Read to Earn' program! For each article you read, earn points and access exclusive rewards. Sign up now and start accumulating advantages.
