Doctorcrypto About RSS Subscribe
Doctorcrypto
Home › Latest › A stolen coin can be returned. A leaked identity cannot.
Latest

A stolen coin can be returned. A leaked identity cannot.

By Priya Chen · · 2 min read

The rush to onboard billions of AI agents into digital finance risks recreating one of the oldest mistakes in data security: building centralized troves of personal information that become irresistible targets for attackers, warns Evin McMullen, CEO and co-founder of Billions.

The Honeypot Problem

For years, companies have collected and stored sensitive personal data in centralized databases—names, addresses, biometric identifiers and financial records. These vast repositories, often described as "honeypots," concentrate valuable information in single locations, making them prime targets for hackers. Each breach exposes millions of people whose most intimate details end up circulating on the dark web.

The distinction McMullen draws is stark. When cryptocurrency is stolen, there are often mechanisms to trace, freeze or return the funds. Blockchains are transparent, and stolen assets can sometimes be recovered. But a person's identity is a different matter entirely—once leaked, it cannot be revoked, reissued or truly reclaimed.

A stolen coin can be returned. A leaked identity cannot.

Scaling the Mistake

The concern grows sharper as artificial intelligence agents begin to proliferate across the digital economy. These autonomous programs will increasingly transact, verify credentials and act on behalf of humans and organizations. If they are built atop the same centralized identity architecture that has already failed people repeatedly, the scale of potential harm multiplies dramatically.

McMullen argues that handing billions of AI agents the same flawed infrastructure would compound existing vulnerabilities rather than solve them. Instead of learning from past breaches, the industry risks industrializing the honeypot model at a scale never seen before.

The proposed alternative centers on verification systems that don't require hoarding sensitive data in the first place. Key principles include:

  • Proving identity or credentials without exposing the underlying personal information
  • Decentralizing data so no single breach can compromise millions
  • Giving individuals control over what they share and with whom

A Call to Rebuild

The message is ultimately a call to reconsider how digital identity is architected before the AI agent economy locks in the current model. Privacy-preserving approaches, McMullen suggests, offer a path to enable trust between humans and machines without creating fresh honeypots for attackers to raid.

As AI agents move from novelty to necessity, the choices made now about identity infrastructure will determine whether the next wave of technology protects users or exposes

Was this useful?👍 Yes👎 No