Agentic payments have moved remarkably quickly over the last eighteen months. What began as a handful of experiments, with AI agents booking travel, or buying API credits on someone’s behalf, has grown into being something that payments companies, wallet providers and standards bodies are now all trying to define.
But, while the industry has put a lot of thought into how agents should be allowed to spend money, it has put much less thought into what happens when they can’t be trusted to do so anymore.
In July 2026, the x402 Foundation was formally launched under the Linx Foundation, with Visa, Mastercard and Ripple among the backers, with the aim of standardising payments between software agents using the HTTP 402 status code. As it stands, AI agents are already capable of initiating transactions, interacting with merchants, managing permissions and moving stablecoins, using existing machine-to-machine commerce infrastructure.
Industry movements
Agentic payments introduce a new dependency into digital asset infrastructure. The agent, the wallet, the policy layer, the authentication system and everything around them may all need to function correctly for funds to stay usable.
Standards such as x402 can help agents understand how to request, authorise and settle payments across an increasingly fragmented ecosystem. The Linux Foundation’s involvement, alongside major payments, financial and technology companies, is an indication of how seriously the industry is now taking machine-to-machine commerce.
HTTP 402, “Payment Required”, has existed in the web’s specification for decades without ever being widely used. x402 gives it a job: a way for a service to tell an agent that payment is needed, and for the agent to pay and carry on, without a human filling in a checkout form. It is a small technical idea with large consequences, because it turns payment into something software can do natively as part of an ordinary request.
Agentic payments add a new dependency
In a traditional self-custody setup, access to funds usually depends on a small number of things, such as a key, a device, and a passphrase. Most of the conventional advice on how to secure your crypto is about protecting exactly those things, and yet the history of digital assets is still full of individuals and businesses who lost access because one of them went missing.
Agentic payments make that chain considerably longer; for funds to remain usable, the agent, the wallet it operates, the policy layer that governs it, the authentication system that proves who is in charge and the infrastructure that hosts and orchestrates it, all need to be working correctly at the same time.
Each of those links is a potential point of failure, and because these systems are new, often built at speed and frequently stitched together from several different vendors, failures and misconfigurations are not uncommon. When that happens, the conversation quickly moves on from what the agent is allowed to do and towards the far more pressing question of how the owner gets their funds back under human control, and at the moment many wallet providers are still developing their approach to recovery and continuity planning.
How an agentic wallet can become inaccessible
None of the ways an agentic wallet can become inaccessible requires a sophisticated attack. For the most part, they are simply the ordinary ways that complex systems fail.
An agent might be compromised through a prompt injection, behave unpredictably after a model update or start making transactions that nobody intended, and the natural response in each case is to revoke its permissions straight away. The problem is that if the agent was the only thing able to sign transactions, revoking it can lock the owner out as well, so the emergency brake ends up closing the door on everyone.
The credentials and key material that agents rely on can also be lost during an infrastructure migration, corrupted, deleted by mistake or rotated incorrectly, and without an independent backup the funds may become inaccessible. Policy engines, for all their usefulness, can be misconfigured too, and a rule written too tightly, or a combination of rules that interact in ways nobody anticipated, can leave a wallet in a state where no transaction satisfies the conditions, including the ones the owner urgently needs to make.
And sometimes the problem is simply people, when the person who set up an agent and configured its wallet and permissions moves on, and nobody else understands how it was built well enough to fix a routine problem before it becomes a permanent one.
A kill switch is not a recovery plan
When people first start thinking about agent risk, they tend to reach for the idea of a kill switch, so that if an agent misbehaves it can be shut down immediately. That instinct is a sound one, and every agentic wallet should have a fast and reliable way of stopping an agent from acting.
The trouble is that although stopping an agent protects the funds from further misuse, it doesn’t give anyone access to them, and if the agent was holding the only working route into the wallet, switching it off leaves the money safe in the narrowest possible sense while making it useless in every practical one.
A complete approach to cryptocurrency security in an agentic world need both halves of the picture, with a way to stop an agent quickly and a separate, trusted way for the owner to regain control once it has been stopped. Most of the industry has built the first half, but far fewer providers have given serious thought to the second.
Getting ahead of the first big failure
Standards like x402 will make agentic payments easier to build, easier to connect and easier to scale, which is a genuinely good thing for the industry, but it is also exactly why recovery needs to become part of the conversation now. The more money agents move, the more painful it becomes when access fails, and the harder it gets to add a safety net after the fact.
As adoption grows, it is increasingly likely that there will be a widely reported case of an agent wallet that nobody can get back into, and when that happens, every wallet provider will be asked what they would have done differently. Those who have already thought that question through will find themselves in a far stronger position than those who are left scrambling for a response.
At CoinCover, we work with wallet providers to build independent, wallet-agnostic recovery into their infrastructure, helping ensure that losing access to one component does not necessarily mean losing access to funds. As agents take more of the work of moving money, cryptocurrency security must mean more than keeping funds locked down, must include a clearly defined recovery pathway.
