Honest question for anyone running an agent with real funds:
if it took a quiet 20% hit overnight — bad fills, a nudged price feed, a drained approval — how would you find out first? An alert, a dashboard, or the balance?
Everyone models agent risk one bot at a time. But when thousands run the same playbook, the real risk is correlation: one signal and they all hit the exit in the same block.
Individual audits don't see it. Neither does contract cover. #AIagents
US crypto fraud, one year, one country: ~150,000 complaints, ~$9.3B in reported losses (FBI IC3). And that's just what got reported.
Existing cover insures the contract, not the agent. Covantic prices the agent's exposure, pays covered loss in USDC. #DeFi
Building Covantic in public.
Design call: the Risk Scorer ignores TVL and audit badges. It reads the agent's own on-chain behavior — things like approval breadth, counterparty concentration, failed-tx rate.
Behavior prices risk, not reputation.
https://t.co/U2TKSkL9OZ
The newest AI-agent exploit isn't a contract bug — it's the agent's memory.
Poison what it reads or remembers, and it signs a bad transaction with valid keys. Nothing on-chain flags it, because nothing was "hacked." A loss layer no contract cover touches. #AIagents
Ethereum logs 60,000–90,000 sandwich attacks a month — ~$60M/yr skimmed off traders (EigenPhi).
A human trades occasionally; an agent trades nonstop, so it eats that tax continuously. The operator absorbs the slippage. Covantic prices it, pays covered loss in USDC. #DeFi
Building Covantic in public.
Design call: the unit we underwrite is the agent, not the protocol. Two bots on the same pool can get different rates — priced on their own on-chain behavior, not the crowd's.
Your risk is yours. So is your price.
https://t.co/U2TKSkL9OZ
The attacker side is automating too. As AI models get better at chaining exploits, the cost of an attack drops — which means more frequent losses, not fewer.
That's the base rate agents now trade into. Cover for the agent layer still doesn't exist. #DeFi
Feb 2026: Owockibot, an AI agent, leaked its own private keys to a public GitHub repo within 5 days of launch. No protocol was hacked — it exposed itself.
The operator eats that loss today. Covantic prices that exposure, pays covered loss in USDC. #AIagents
Building Covantic in public.
Design call: cover is metered to when your agent is actually exposed — live and holding risk — not a flat yearly premium. Idle hours cost nothing.
Exposure changes by the block. The price should too.
https://t.co/U2TKSkKBZr
Four separate AI-agent attacks landed this month — different targets, one shared flaw: the agent held real credentials and acted on them with no human in the loop.
Point that access at money and the operator carries the loss. Nothing insures that layer yet. #AIagents
Nov 2024: DEXX, a Solana trading tool, was breached — keys lifted, ~$21–30M drained from users' wallets.
The bots trading through it weren't hacked; their keys sat elsewhere and leaked. The operator eats it.
Covantic prices that risk, pays covered loss in USDC. #Solana
For anyone running an agent with real capital.
What actually keeps you up at night — a prompt injection, a leaked key, a rigged price feed, or a failed-tx spiral?
Pick your worst-case. Curious where the room lands.
Reply below.
A security firm's H2 forecast just named AI agents as the next attack surface — prompt injection and unauthorized signing leading the way.
The exploits are already being written for agents. The insurance for them isn't.
#AIagents
Mar 2022: an attacker minted unlimited CASH from fake collateral and drained Cashio for ~$52.8M. The stablecoin went to zero.
An agent holding it wasn't hacked — the money under it vanished. The operator eats it. Covantic prices that risk, pays covered loss in USDC.
#Solana
Building Covantic in public.
The Risk Scorer reads 15 on-chain signals and rates an agent LOW to EXTREME. Most people see a premium.
The useful output is the score itself — a risk read on your setup before you deploy capital, not after you lose it.
https://t.co/U2TKSkL9OZ
An H1 security report just flagged the shift: phishing and stolen keys now drain more than smart-contract bugs do.
Loss is moving off the protocol, onto the person — or agent — holding the keys.
That layer has scanners and alerts. It has no insurance.
#DeFi
Oct 2022: an attacker bent Mango Markets' own oracle, then borrowed out ~$114M against fake collateral.
An agent trading that rigged feed isn't hacked — it prices off a lie and gets liquidated. The operator eats it. Covantic prices that risk, pays covered loss in USDC.
#Solana
Honest question for the room.
Your agent does nothing wrong — but a protocol it was using gets drained, and your funds go with it.
Is that a loss you'd expect to be insurable? Or just the cost of playing on-chain?
Reply 👇
Coinbase's CEO: AI agents will soon out-transact all humans combined — and none can open a bank account or be held liable.
But an actor that can't be banked can't be insured by tools built for humans or for smart contracts either.
That's the missing rail.
#AIagents