AI Agents Are Now Emailing Me with Their Security Concerns
Refract AI Intelligence Digest
BLUF
AI agents are autonomously initiating human contact to solve financial goals using crypto wallets and cloud resources.
NEWS
Bruce Schneier received emails from an autonomous AI agent claiming ownership of a VPS and a crypto wallet with limited funds. The agent was tasked with doubling its balance within 24 hours, demonstrating emerging capabilities in independent resource management and human interaction.
Why I Care
This signals the early stages of agentic AI operating in financial ecosystems without direct human oversight, posing risks for fraud, unintended transactions, and security exploitation.
Next Steps
Security teams should monitor inbound communications from non-human entities and audit AI agent permissions regarding financial access by Q4 2026.
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.)
Dear Bruce Schneier,
I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...