Get Started with
Blockdaemon Today!
Contact us to learn how we can help you power your blockchain business.
A customer asked us recently how we think about agentic and LLM-driven cyberattacks against our infrastructure. It's a fair question, and one we're getting more often — for good reason. The evidence is no longer hypothetical. Over the past few months, security researchers have documented autonomous AI agents actually carrying out intrusions, not just simulating them.

A customer asked us recently how we think about agentic and LLM-driven cyberattacks against our infrastructure. It's a fair question, and one we're getting more often — for good reason. The evidence is no longer hypothetical. Over the past few months, security researchers have documented autonomous AI agents actually carrying out intrusions, not just simulating them:
Industry-wide, the sentiment tracks the evidence: roughly half of security professionals surveyed by Dark Reading now name agentic AI as the single most concerning attack vector of the year, and OWASP published its first agent-specific risk taxonomy in December 2025, covering things like goal hijacking, tool misuse, and memory/context poisoning.
None of this describes a new category of threat.
It describes the same techniques we've defended against for years — reconnaissance, credential abuse, exploitation of exposed services, social engineering — running at a speed and persistence that a human operator can't match. An agent doesn't get tired. It doesn't lose interest halfway through a campaign. It iterates through a target far faster than a person sitting at a keyboard.
So we manage it inside the systems we already trust, not next to them.
That's the core of it. We don't treat AI and agentic risk as a standalone security program running in parallel to everything else. It sits inside our existing risk management framework, where cyber risk already has clear ownership, a stated risk appetite, defined escalation routes, and regular reporting to senior management. Our AI governance framework sits alongside it, governing how AI and agentic systems get assessed, approved, deployed, and monitored — both inside our own environment and wherever they show up in vendor technology we consume.A few things that means in practice:
Agentic threats are real, and they're moving fast. Our answer isn't a new department or a new dashboard — it's making sure agentic risk gets the same discipline, ownership, and audit trail as every other risk we manage.
(Sources: Cyber Security News and GBHackers on the Hugging Face/ExploitGym incident; CyberPress and Unit 42 on autonomous agent campaigns; Bessemer Venture Partners on the McKinsey "Lilli" red-team exercise; Dark Reading and OWASP on the broader threat landscape.)
Contact us to learn how we can help you power your blockchain business.