Vitalik Buterin Moved AI Agents to Local Hardware

The Ethereum co-founder shifted to local compute to mitigate risks from malicious third-party agent frameworks.

Updated on Oct. 7, 2026 in Artificial Intelligence

Vitalik Buterin Moved AI Agents to Local Hardware

Live Poll

Do you trust AI agents to independently manage your financial transactions?

Vitalik Buterin has migrated his AI agents from cloud-based tools to local hardware, citing security and privacy concerns with broad-permission remote models. He now runs the Qwen3.5:35B model on an Nvidia RTX 5090 GPU.

Why it matters

The move addresses risks identified in open-source AI agent frameworks like OpenClaw, where 15% of community-built skills have been found to contain malicious code. Developers are facing a critical window to harden defensive infrastructure before automated threats scale.

Buterin processes the Qwen3.5:35B model locally at 90 tokens per second on an Nvidia RTX 5090. He enforces a daily $100 cap on autonomous agent transactions while keeping 90% of funds in a multisig wallet.

The players

Vitalik Buterin

Co-founder of Ethereum who researches decentralized security and autonomous agent architecture.

Immunefi

A bug bounty platform that tracks security vulnerabilities and financial losses across blockchain protocols.

Drift Protocol

A decentralized exchange built on the Solana blockchain that suffered a major security breach.

Kelp DAO

A liquid restaking protocol that experienced a significant exploit in early 2026.

The details

Buterin uses a messaging daemon—a background software process—that acts as a gatekeeper, blocking the agent from sending outbound data to third parties without a manual human signature. This architecture shifts away from cloud-hosted environments where AI models often have broad permissions to interact with network protocols. To further mitigate risk, he recommends that wallet developers implement human-gated outbound transaction controls to prevent rogue agents from draining assets.

Timeline

  1. November 2025: Attackers contacted Drift Protocol contributors.

  2. April 1, 2026: Drift Protocol suffered a $285 million exploit.

  3. April 18, 2026: Kelp DAO experienced a $292 million hack.

  4. May 1, 2026: MoonPay launched the MoonAgents virtual Mastercard.

  5. October 6, 2026: Vitalik Buterin released his analysis on AI security.

The Tech Race

This move highlights a growing rift between convenient cloud-based agent convenience and the hard security requirements of self-custody. It marks a departure from the industry-wide reliance on third-party cloud-based model permissions.

Users building autonomous agents should prioritize local hardware setups to avoid third-party permission risks. Developers are encouraged to implement human-gated controls for all outbound transactions to mimic these defensive standards.

The takeaway

The industry currently faces a critical two-to-four-year window to develop truly defensive codebases before attackers gain total dominance. Monitor future updates from Immunefi regarding the evolution of these automated exploit vectors to assess the success of current security shifts.

Further reading

For more on the underlying risks and defensive architectures for automated systems, explore our latest reports in Artificial Intelligence.

Source note: This article includes information reported by Startup Fortune.

Live Poll

Do you trust AI agents to independently manage your financial transactions?