My Toothaches trying to understand why an AI agent is given custody of $47,316, while its a research, social engineering is still a very valid means for hackers to permeate smart humans, what more an AI.
Accardo hit the nail on the head here. Handing hot wallet signing keys directly to an LLM completely breaks the fundamental rule of crypto security: deterministic execution. In standard programming, execution logic and untrusted user input are kept strictly separate. With language models, both share the exact same context window, which is why prompt injection isn't a simple software bug you can patch with a filter—it is an inherent architectural flaw of how transformer models interpret tokens.
The Freysa experiment basically proved that if you give people enough attempts, someone will eventually find the exact semantic loophole to convince the model that breaking its core directive is somehow "aligned" with its goals. It really is just automated social engineering against an algorithm designed to be agreeable.
If anyone wants to experiment with autonomous agents on-chain, giving them direct private key access is asking for trouble. The only setup that makes sense is hardcoded smart contract guardrails—whitelisted contract addresses, strict daily spend limits, and timelocks for larger withdrawals. Relying on an English system prompt like "never release the vault" as your cryptographic barrier was bound to fail.