The paper reviews four studies that combine blockchain and AI to secure data sharing, model integrity, and autonomous decision-making in distributed systems. It highlights how blockchain’s immutability, decentralized consensus, and verifiable provenance can address trust gaps in training data, real‑time monitoring, and automated code remediation. The authors propose a layered architecture integrating hardened models, blockchain‑anchored provenance, AI anomaly detection, and smart‑contract‑governed multi‑agent remediation, and outline open challenges in scalability, privacy‑transparency trade‑offs, and governance.
By Harsh Verma
AgentXploit is a two‑role auditing system that separates repository‑level attack‑path discovery from runtime exploitation for AI agents. The Analyzer Agent traces attacker‑controlled inputs to sensitive operations and records candidate attack paths, while the Exploiter Agent turns these paths into concrete attacks and refines them using runtime feedback. The system is evaluated on AgentXploit‑Bench, a benchmark of 72 reproducible vulnerabilities across 12 open‑source AI‑agent systems, achieving 59.3% end‑to‑end success compared to 38.4% for Codex, and 79.2% attack success on AgentDojo versus 52.7% for AgentVigil.
By Weida Liang, Shi Qiu, Zhun Wang, Simon Sure, Xiaoyuan Liu, Tianneng Shi, Zhaorun Chen, Wenbo Guo, Dawn Song
arXiv:2603. 05786v2 Announce Type: replace-cross Abstract: As AI agents become widely deployed as online services, users often rely on an agent developer's claim about how safety is enforced, which introduces a threat where safety measures are falsely advertised.
By Xisen Jin, Michael Duan, Qin Lin, Aaron Chan, Zhenglun Chen, Junyi Du, Xiang Ren
The paper surveys the growing use of AI agents that modify external state via the Model Context Protocol (MCP) ecosystem, noting an increase from 27% to 65% of tool use. It argues that when such agents operate on public blockchains, the blockchain execution layer’s properties—irreversibility, signing authority, continuous autonomy, and sequence-level composition—reshape the threat model, making failures irreversible. The authors organize existing MCP-security literature into an attack-surface taxonomy, present a Web3 risk-mapping matrix linking attack classes to amplified impacts and mitigations, and conclude that current defenses are inadequate, stopping fewer than 30% of attacks and less than 3% of model-level safety failures.
whyItMatters":"The study highlights that AI agents acting on Web3 introduce irreversible risks that conventional software security cannot address, underscoring the need for stronger, blockchain-aware safeguards."
By Rabimba Karanjai (Larry), Yang Lu (Larry), Nour Diallo (Larry), Wujie Xiong (Larry), Lei Xu (Larry), Weidong (Larry), Shi
arXiv:2606. 18619v1 Announce Type: cross Abstract: The advent of agentic vulnerability detection is already becoming a watershed moment for software security.
By Zhengxiong Luo, Mehtab Zafar, Dylan Wolff, Abhik Roychoudhury
The paper introduces Fetch.ai, an industrial-strength architecture that blends classical multi-agent system principles with modern AI capabilities. It features a decentralized foundation of on-chain blockchain services for identity, discovery, and transactions, a development framework for secure, interoperable agents, a cloud-based deployment platform, and an agent-native LLM that translates human goals into multi-agent workflows. A decentralized logistics use case demonstrates autonomous agents dynamically discovering, negotiating, and transacting securely.
By Michael J. Wooldridge, Attila Bagoly, Jonathan J. Ward, Emanuele La Malfa, Gabriel Paludo Licks
arXiv:2606. 09935v1 Announce Type: cross Abstract: AI-powered agents are increasingly embedded in continuous integration and continuous delivery/deployment (CI/CD) pipelines to autonomously review pull requests (PRs), triage issues, and maintain codebases.
By Jafar Isbarov, Umid Suleymanov, Ilia Shumailov, Murat Kantarcioglu
arXiv:2607. 16660v1 Announce Type: cross Abstract: The increasing adoption of Large Language Models (LLMs) as AI components in modern software systems introduces distinct security risks to the software supply chain.
By Mahzabin Tamanna, Elizabeth Lin, Sparsha Gowda, Laurie Williams, Dominik Wermke
arXiv:2606. 12797v1 Announce Type: new Abstract: Agentic large language model systems that autonomously invoke tools, maintain persistent memory, and execute multi-step plans are increasingly deployed in public-facing domains, including government services, healthcare triage, and financial advising.
By Md Jafrin Hossain, Mohammad Arif Hossain, Weiqi Liu, Nirwan Ansari
The paper introduces the Agile‑V Assurance Spine, a cross‑domain transition contract designed to manage the assurance of outputs from agentic engineering systems across software, firmware, and PCB domains. It specifies that evidence is only accepted when it demonstrates required properties through an authoritative source profile, is tightly bound to the exact artifact and policy baseline, stays current with declared dependencies, and meets risk‑appropriate independence and authority. Gate decisions are recorded as receipts, approvals and exceptions are scope‑ and time‑bounded, and authorization is rechecked at the effect boundary before any merge, deployment, flashing, release, or fabrication step.
By Christopher Koch
AI coding agents are being adopted at historic speed, yet security and risk concerns remain the primary barrier to scaling agentic AI across organizations. Existing security controls for coding agents are not systematically distributed to engineering teams, and vendor-native solutions introduce ecosystem dependencies that may not suit every deployment context.
arXiv:2606. 30970v1 Announce Type: new Abstract: Autonomous AI agents increasingly perform consequential actions on behalf of human principals, including financial transactions, external communications, and enterprise workflows.
By Anuj Kaul, Qianlong Lan, Pranay Gupta