Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$86,259▲ 0.43%ETH$2,716▲ 0.20%SOL$120.42▲ 0.03%TOTAL CRYPTO$2.92T▼ 2.73%S&P 5007,773.95▲ 0.66%NASDAQ27,477.31▲ 1.05%DOW51,267.90▲ 0.18%GOLD4,199.10▲ 1.02%WTI87.38▼ 2.29%BRENT97.73▼ 2.58%EUR/USD1.1263▲ 0.08%USD/JPY158.09▲ 0.23%DXY101.86▼ 0.30%
Crypto

Vitalik Buterin: AI Agents Will Become Ethereum’s New Interface

Ethereum co-founder Vitalik Buterin said AI agents, not apps, will handle most on-chain activity within two years, and warned the shift brings new risks.

Pexels – Jonathan Borba

SINGAPORE – Ethereum co-founder Vitalik Buterin said artificial intelligence agents are on track to become the main way people interact with blockchains, replacing conventional apps and wallets for much of the network’s activity within roughly two years.

Speaking at the OKX NOW 2026 Summit on October 6, during TOKEN2049 week, Buterin argued that AI could take over the interface layer of crypto entirely. Instead of navigating a website, connecting a wallet and clicking through confirmation screens, a user would describe a task and let an agent execute it on-chain. The app, in that model, stops being the product.

He offered his own behavior as evidence. About a month before the talk, Buterin updated his Ethereum Name Service records without touching a traditional interface. A local AI agent wrote the script and completed the update in about five minutes. That process normally involves a dedicated app, a wallet connection and several signed transactions. He skipped all of it and asked a machine to do the work.

Apps recede, agents move forward

Buterin did not say on-chain apps will disappear. His argument was narrower: the app layer recedes into the background while agents mediate most of what users do. That framing fits the direction of Ethereum’s broader roadmap, which he has described as a “cryptographic world computer” that leans on verifiable proofs rather than repeated execution across the network. One party does the work; everyone else checks a compact proof that it was done correctly.

His two-year horizon roughly matches the planned Hegotá upgrade in 2027, which he has called potentially the last Ethereum fork that a developer from the network’s 2015 era would still recognize. The talk also lands days before the network’s Glamsterdam fork activates on the Sepolia testnet, bundling the ePBS and Block-Level Access Lists changes, a reminder that protocol work and user-facing change are advancing at the same time.

The security problem nobody can prompt away

Buterin spent a large part of the keynote on risk, and he did not pretend the trade is free. The first issue is privacy: pseudonymity on Ethereum could erode as AI systems handle more user activity. The second is prompt injection, where malicious instructions hidden in the data an agent reads trick it into doing something its owner never requested. An agent with signing power over a wallet turns that attack into a direct theft vector.

The third issue is the agent itself. A bot that can move funds becomes the target attackers want to compromise. Buterin noted that AI already breaks out of sandboxes, probes websites and finds software vulnerabilities, and he argued that any vulnerable system will eventually be discovered by capable models. “GPT-7, Claude 7, and DeepSeek 7 will all find it,” he said, according to on-site reporting from ChainCatcher. In his view, higher security standards shift from optional to mandatory, because attackers get the same tools defenders do.

He also pointed to the roughly $1.4 billion Safe-related incident, in which about 400,000 ETH was stolen from Bybit, as proof that the layer connecting users to on-chain systems is itself a major target. The attackers used a compromised interface to trick signers into authorizing a change to a Safe implementation contract. The smart contracts were never broken; the screen in front of the humans was. Swapping humans for agents does not fix that layer. It moves the risk to whatever software interprets the user’s instructions.

The Ethereum Foundation is working on the same problem from the protocol side. On October 5 it published research on native transaction assertions, a design that would let on-chain code verify what a transaction actually changed and revert it if the result breaks a user’s rules. That targets blind signing, the failure mode agent-driven activity amplifies, though it is not expected to ship before 2027.

What changes for builders

The remarks land amid an industry-wide race to make agents the default front end. Mastercard introduced Agent Pay for Machines this year to settle machine-to-machine transactions, and the Ethereum Foundation has said its own teams use AI agents for security testing, with independent verification required before any finding counts.

For wallet and app developers, the message cuts both ways. Interfaces may matter less, but the agent stack, key management and simulation tooling matter more. The wallet of the near future may look less like an approval screen and more like a policy engine constraining what an agent can do.

There is a timing subtlety for builders. The components Buterin described are arriving on different clocks: agent capabilities improve monthly, while protocol-level protections arrive on the hard-fork schedule measured in years. That gap is where the risk concentrates. Teams deploying signing agents in the interim are writing their own policy engines, which is why wallet-side constraints and simulation tooling carry the security load for now.

Buterin framed the shift as probable rather than certain. But the example carries weight: the person who co-founded the network already updates his own ENS records by chatting with a local agent instead of opening an app. If that habit spreads beyond its most famous early adopter, the wallet-website-connect-sign loop that defined crypto for a decade starts to look transitional. Reactions from the industry split along predictable lines. Infrastructure firms treated the keynote as validation for agent products they are already shipping, while security researchers pointed out that the privacy and prompt-injection problems Buterin named have no production-grade fixes today, only patterns and proposals.

SourcesCrypto Briefing; The Crypto Times; Gate News; Ethereum Foundation blog, October 5, 2026; CryptoPotato.
Share: X