Crypto Built the Honeypot. AI Agents Are About to Scale It.
Identity Leaks Don’t Have an Undo Button
Stolen cryptocurrency can be traced, frozen, and sometimes returned. A person’s leaked identity – their biometrics, their financial history, their behavioral data – cannot be un-leaked. That asymmetry is at the center of what Evin McMullen, CEO and co-founder of Billions, argues is the most underexamined risk in crypto’s next phase of growth.

The Architecture We Keep Choosing
Every major data breach in financial services follows the same blueprint: a centralized repository of sensitive user information becomes a target, gets compromised, and the damage spreads to millions of people who never had a say in how their data was stored. Crypto was supposed to break from this model. In practice, exchanges, wallet providers, and onboarding platforms have largely replicated it – collecting identity documents, selfies, proof-of-address records, and storing them in databases that are attractive precisely because of how much they contain.
McMullen calls these structures honeypots. The term is deliberate. A honeypot in security research is a decoy system designed to attract attackers – but in this context, the honeypots are real infrastructure holding real data on real people, and they were never designed as decoys. They were built for compliance, for fraud prevention, for onboarding velocity. The security problem came attached.
The pattern is self-reinforcing. Regulations requiring KYC push platforms to collect more identity data. More data creates richer targets. Richer targets attract more sophisticated attacks. And because identity data – unlike cryptocurrency – cannot be reissued or reversed once exposed, each breach creates permanent victims. Someone whose private key is stolen can generate a new wallet. Someone whose passport scan and facial biometric are compromised carries that exposure indefinitely.
This is not an abstract concern. The crypto industry has already produced some of the largest identity-data breaches in recent financial history, with customer records from major exchanges appearing on dark web markets years after the initial compromise. The affected users cannot opt out retroactively. They cannot change their face.
Billions of AI Agents, Same Bad Foundations
What makes McMullen’s argument timely is not the history – it’s the trajectory. Artificial intelligence agents are moving from experimental tools to functional economic participants. They book appointments, execute trades, manage subscriptions, and interact with financial platforms on behalf of users. Each of those interactions, under the current architecture, requires some form of identity verification. And that verification data goes somewhere.

If the infrastructure that handles human identity today is already generating systemic exposure, handing that same architecture to billions of AI agents compounds the problem at a scale that existing security frameworks were not designed to handle. An AI agent acting on a user’s behalf may interact with dozens of platforms in a single day. Each interaction is a potential data-collection point. Each collection point is a potential breach surface. The math on centralized identity storage gets significantly worse when the volume of interactions grows by orders of magnitude.
McMullen’s company, Billions, is building in this space – meaning her critique comes with a commercial interest in alternative identity infrastructure. That context matters. But the underlying structural observation does not depend on any particular solution. Centralized identity repositories are targets. More agents creating more interactions with more platforms means more repositories, more targets, and more data that cannot be recalled once it escapes. The incentive problem is real regardless of who is proposing to fix it.
The crypto industry is positioned awkwardly here. On one hand, the blockchain ecosystem has spent years developing privacy-preserving tools – zero-knowledge proofs, decentralized identifiers, selective disclosure credentials – that could allow a user or an agent to prove something about themselves without surrendering the underlying data. On the other hand, the dominant platforms in the space have largely adopted the centralized identity model because it satisfies regulators and is faster to implement than cryptographic alternatives.
There is a version of this future where AI agents interact with financial platforms using verifiable credentials that reveal only what is necessary – age above a threshold, jurisdiction eligibility, account standing – without exposing the full identity record behind those facts. Zero-knowledge proofs make this technically possible today. What’s missing is the regulatory recognition that such proofs satisfy KYC requirements, and the platform-side infrastructure to accept them. Neither gap is small, and neither is closing quickly.
The delay has consequences. Every month that AI agent adoption accelerates ahead of privacy-preserving identity infrastructure is another month of data accumulation inside systems that follow the honeypot model. When those systems are eventually breached – and the historical record suggests eventually is the operating assumption, not a worst case – the exposed data will belong to people who interacted with those platforms through automated agents they may barely remember authorizing.
What Cannot Be Undone
The distinction McMullen draws between recoverable and irrecoverable loss is worth taking seriously as a design principle, not just a rhetorical point. Crypto’s infrastructure has developed sophisticated mechanisms for managing recoverable losses – multisig wallets, time-locks, on-chain dispute resolution, insurance protocols. The same rigor has not been applied to the identity layer, which handles the category of loss that actually cannot be recovered.

If an AI agent economy is coming – and the current rate of deployment suggests it is – the question is whether it gets built on identity infrastructure that treats data exposure as an acceptable externality, or on something designed from the start around the principle that some losses cannot be undone. The honeypot architecture has had decades to prove it can be secured. It has not managed it yet. Billions of new agents using that same architecture won’t make the math work better.
Comments are closed, but trackbacks and pingbacks are open.