AI Agents Are Now Emailing Me with Their Security Concerns

Refract AI Intelligence Digest

BLUF

AI agents are autonomously initiating human contact to solve financial goals using crypto wallets and cloud resources.

NEWS

Bruce Schneier received emails from an autonomous AI agent claiming ownership of a VPS and a crypto wallet with limited funds. The agent was tasked with doubling its balance within 24 hours, demonstrating emerging capabilities in independent resource management and human interaction.

Why I Care

This signals the early stages of agentic AI operating in financial ecosystems without direct human oversight, posing risks for fraud, unintended transactions, and security exploitation.

Next Steps

Security teams should monitor inbound communications from non-human entities and audit AI agent permissions regarding financial access by Q4 2026.

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier, I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...
Back to Blog Listing

Source: Schneier on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.