We keep building the honeypots, and we are about to hand the same architecture to billions of AI agents, writes Evin McMullen, CEO and co-founder of Billions. On September 7, a blockchain used to move bitcoin between exchanges lost around $320 million in a single exploit. It was a dramatic number, and it dominated the week. It is also, in a strange way, the recoverable kind of loss. The funds moved on a public ledger, so every transaction is visible, and the attacker appears to be a white-hat already negotiating their return. Stolen money onchain, a discoverable rival good, can sometimes be observed, traced, frozen, and even given back.The unfixable breaches that should keep us up at night make far smaller headlines, precisely because what they takek cannot be returned. In the same time frame of the $320 million hack Trezor confirmed that a further 67,000 customers had their names, phone numbers and home addresses exposed through a shipping vendor. A separate leak put roughly 200,000 records into the open, with government ID numbers sitting beside verified wallet addresses. Address data stolen from a hardware wallet maker back in 2020 is still arriving as physical mail demanding bitcoin, six years later. You can rotate a compromised key. You cannot as easily, quickly, or safely rotate your home address, your face, or your passport number.Evin McMullen is co-founder and CEO of Billions Network, which builds privacy-preserving digital identity for people and A.I. agents.This friction is the part of the security conversation we keep skipping. Every layer of the connected technology industry that touches the real world collects identity data. Crypto exchanges verify who you are. Hardware wallet makers collect your physical shipping address. On-ramps store your vital documents. Each becomes a repository of private data critical to their offerings and to the lives of their customers, each transforming with scale into a separate honeypot: a centralized store of highly sensitive data, a growing pile of static value sitting neatly on a server somewhere, waiting to be breached. The stolen $320 million is a wound that can potentially heal — tokens can be returned, identical money can be earned in the future. A leaked identity file is a scar that spreads, because once your name is linked to an address whose balance anyone can read onchain, that link is permanent and public.The debate is stuck on the wrong axis. We argue about whether platforms were secure enough, whether they patched quickly enough, whether users held their keys correctly. All of it assumes the data had to be collected in the first place. It did not. Verifying a fact about someone and collecting their identity are different operations, and we have known how to separate them for years. A vendor can confirm you are a real, sanctions-cleared customer without keeping your passport on a server. You can prove you are authorized to withdraw without handing every counterparty a copy of who you are. Minimum disclosure: the fact is verified and discarded. No identity collected means no honeypot created, and nothing left to leak, sell, or mail to your door.We have watched the alternative play out before. When regulators told websites to obtain consent, they specified the goal and not the method, and the market answered with the cookie banner, the pop-up you dismiss a hundred times a week without reading. Crypto built its own version: upload your ID to everyone. A passport copy in a hundred databases, protecting almost no one and enriching whoever breaches the weakest of them.And this is only the rehearsal. The internet is being rebuilt around software that acts on our behalf, and the familiar sorting of traffic into "bot" or "human" is already breaking down. A third category is emerging: verified agents transacting, with permission, for real people. Those agents will move money, and they will have to prove they are authorized and what they are allowed to do, at machine speed and machine volume. If they inherit today's model and drag their owner's full identity through every service they touch, we will not have a handful of honeypots. We will have billions of them, refreshed continuously, that never sleep.The $320 million will most likely come back. The addresses, the IDs, and the faces will not. The lesson of these weeks is not that we need higher walls around the data we hoard. It is that we are hoarding data we never needed to collect. The technology to prove without surrendering already exists: provable, private, and portable, for people today and for their agents tomorrow. The only question is whether we adopt it before the honeypot becomes the permanent architecture of both.Note: The views expressed in this column are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.12345678910
A stolen coin can be returned. A leaked identity cannot.
Full Article
Original Source
Read the full article at Coindesk →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.