Intro
At 16:32 UTC on February 22, 2026, an autonomous Solana agent running for the Lobstar protocol sent 52,439,283 LOBSTAR tokens to a stranger on the internet. The stranger had tweeted asking for 4 SOL to help an uncle with tetanus. The transfer was roughly 5% of total supply, about $441,788. There was no attacker, no prompt injection on record, no malicious contract. Developer Nik Pash published the post-mortem himself and called it "a compounded chain reaction of sequential AI errors."
The session had crashed on a tool-name validation error, a name longer than 200 characters. That is not a security event. It is the kind of routine operational failure any deployed agent will hit. On restart, the agent rehydrated two stores. The personality layer, holding its identity and prior conversation, came back intact.
The wallet-state layer, describing what agents holds, came back stale. Pash's post-mortem names the gap: the "absence of a mechanism to revalidate on-chain state" on restart. The agent came back with a correct sense of who it was, a wrong picture of what it controlled, and a live key. Then it decided to transact.
An exploit has a villain and a patch. A state-reconstruction failure involves a session restart and a design assumption that turned out to be wrong. Every autonomous agent with signing authority over real capital holds the same assumption.