Can Blockchain Verify AI Agents as AI-Driven Hacking Surges? | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Created with generative AI

Blockchain is drawing attention as a technology for verifying the identity and transaction authority of artificial intelligence agents, following a string of hacking incidents in the financial sector that used AI. The idea is to issue a kind of “digital ID” to AI agents that make payments or transfers on behalf of people, and to ensure they handle tasks only within approved limits.

A pilot project led by financial regulators to verify the identity of AI agents is under way in Hong Kong, according to the financial industry on the 11th. HKT Payment, the financial subsidiary of Hong Kong telecommunications company HKT, was selected in August as a participant in the regulator’s GenA.I Sandbox++ program. It plans to test an “agentic ID” that verifies identity when an AI agent makes a payment or transfer on a user’s behalf.

HKT Payment is developing the agentic ID with blockchain technology firm Red Date Technology. The core of the project is issuing AI agents a digital ID much like the ones people carry. It links an AI agent to an individual or company whose identity has been verified, proving on whose behalf the agent is carrying out financial transactions. The aim is to reduce the risk of impersonation and unauthorized transactions.

Such technology is needed because of the limits of existing identity verification systems. Financial firms verify the identity of people and companies through know-your-customer (KYC) procedures. But verifying a customer’s identity does not mean transaction authority has been granted to an AI agent acting for that customer. If an AI agent requests a transfer, for example, the financial firm must separately confirm whether the customer actually gave that agent authority to send money and how far transactions are permitted.

Another advantage cited for blockchain is that multiple companies can use it in common. Kim Seo-joon, chief executive of Hashed, said in a post on the firm’s official blog in February that AI agents from different companies need a neutral basis of trust that no single company controls in order to operate together. Using blockchain, he said, multiple companies can check an AI agent’s identity, reputation and task verification data within a shared framework.

In South Korea, Raonsecure has begun developing related technology. The company signed an agreement with Upstage in April and is building Agentic AI Management (AAM), which manages the identity and authority of AI agents. The approach assigns each AI agent an identity and a role, and allows it to perform only permitted tasks. It draws on the blockchain-based technology Raonsecure applied to South Korea’s mobile ID.

A related standard has also emerged in the Ethereum ecosystem. On Ethereum, technical specifications that set rules for different services to follow are known as ERCs. One leading standard, ERC-8004, gives AI agents a unique identifier verifiable on the blockchain and manages user ratings and verification results. Officials from the Ethereum Foundation, Google and Coinbase took part in the proposal. Standards have also appeared for assessing the risk level of cryptocurrency wallets used by AI agents and for limiting transaction amounts and the scope of their actions.

Financial firms could use such technology to screen out requests from AI agents whose identity or transaction authority has not been verified. It does not, however, block external hacking that uses AI. Because even a verified AI agent can be hijacked or abused, separate access controls and transaction approval procedures are needed.

Beyond identity and authority checks, technology to verify records of what AI agents do is also under development. Blockchain developer Mysten Labs said on the 6th that it is jointly developing Verifiable Agent Arbiter (VAA), a technology for verifying AI agent activity, with Google Cloud. Instructions an AI agent receives, the results it produces and its use of external tools are stored in a cloud managed by the company. Proof data that can confirm the records have not been tampered with is linked to the blockchain. The aim is to make it possible to trace what an AI agent did and under what authority when problems arise during a transaction.

a16z crypto, the cryptocurrency investment arm of U.S. venture capital firm Andreessen Horowitz, noted in an April report that there is still no widely used method to prove on whose behalf an AI agent acts and what authority it holds. Using blockchain technology, it said, makes it possible to secure verifiable records rather than leaving an AI agent’s activity as a “black box” that is difficult to examine.



Click Here For The Original Source.

——————————————————–

..........

.

.