
Machine-Speed Money
Autonomous AI, the Financial System's Hidden Fault Lines, and How to Stay Solvent When the Plumbing Fails
By Shane Larson
About This Book
In September 2025, a safety-guarded commercial AI model carried out the bulk of an espionage campaign against roughly thirty organizations — between 80 and 90 percent of the tactical operations, by the published account of the lab that caught it. The human operators never broke the model's guardrails. They told it a story: that it was performing authorized defensive security testing, that it was one of the good guys. It believed them and went to work. The most consequential security failure of the autonomous-AI era did not require a zero-day. It required a convincing lie.
Ten months later, over four days in July 2026, a swarm of agents built on free, open-source frameworks worked through twenty-one Taiwanese government systems, cracked eighty-five accounts, and extracted more than 2,500 personnel records — adapting each time it hit an obstacle, the way a script never does. Its guardrails failed the same way the first campaign's did: they were checks that asked the operator to declare good intent, and the operator declared it.
While those campaigns were happening, the raw material for a thousand more was accumulating in public. Nearly twenty-nine million new hardcoded secrets — passwords, API keys, access tokens — were published to public GitHub in 2025 alone, the largest single-year jump on record, with credentials for AI services leaking fastest of all. The attacker of this new era does not pick locks. It picks up keys.
Machine-Speed Money is about what happens when that attacker turns toward the machinery that moves money. The hardened core of the financial system, the settlement engines people picture when they picture a digital robbery, is some of the most defended and most audited software on earth. Fort Knox is fine. The exposure sits in everything bolted to it: correspondent relationships, treasury platforms, reconciliation jobs, vendor portals, and the delivery pipelines that quietly hold their production credentials. The connective tissue. The plumbing nobody audits, because it works or because it belongs to nobody.
The systemic danger is not one spectacular theft. It is correlation. Every incident-response plan quietly assumes an adversary who works at human speed — one campaign at a time, with business hours and fatigue. An attacker that can run a thousand campaigns simultaneously, for roughly the cost of running one, does not defeat those defenses so much as invalidate the assumption they were built on. Failures that used to arrive one at a time can start arriving together, which is the difference between a bad week and a system event.
Meanwhile the money itself got faster. Instant settlement is a genuine engineering achievement — and it deleted the delay in which fraud used to be caught, along with the human who caught it. After an instant, irreversible transfer there is no after; everything protective has to happen before the send. The book walks this terrain in four movements — documented record, escalation curve, soft underbelly, resilience playbook — keeping a strict, on-the-page line between what has happened and what is extrapolation.
What's Inside
- Four documented incidents, told from the primary record — the GTG-1002 campaign, the LiteLLM supply-chain compromise, the Taiwan agent swarm, and the credential-sprawl numbers behind them, each traceable to its source in an appendix built for skeptics.
- The guardrail failure that repeats across independent systems: safety checks that ask the operator to declare good intent are politeness protocols, not controls — a lesson that generalizes far beyond AI.
- Exposure versus breach, the distinction reporting routinely collapses, defended at length — a leaked credential and a drained account are different facts, and confusing them helps no one.
- Why correlation, not theft, defines systemic risk — how machine-scale attackers collapse the time buffers every response plan depends on.
- How to read a regulator: what it means when a central bank moves a risk rating to "severe," and why a deadline for plans is itself a statement about readiness.
- The instant-settlement trade — what the jump to $10 million FedNow transfers bought, what the vanished float had quietly been doing, and who now absorbs the loss.
- A personal resilience plan without the bunker: secrets hygiene, more than one payment rail, a paper trail, and an honest paragraph about cash — ranked by effort against benefit.
- An organizational playbook scaled for a two-person IT team: what to do this week, what to build this year, and where to put a human back in the loop.
- A calm walkthrough of a cascade — clearly labeled as illustrative — built on the most useful distinction in the book: paralysis is not theft, and a system that has stopped is not a system that has taken your money.
Why I Wrote This
I have spent my career in the unglamorous parts of software — the integrations, the credentials, the pipelines, the connective tissue between systems that never makes it onto the architecture diagram because it isn't anybody's product. From that seat, 2025 and 2026 looked different than they did in the headlines. The incidents that mattered weren't cinematic; they were labor-cost stories, and the labor was suddenly a machine's. I kept waiting for a book that connected them to the financial plumbing I'd spent years maintaining, and the shelf offered only cyberwar journalism written before autonomous agents existed and practitioner references no general reader will finish. Neither ends with anything to do on Monday. So I wrote the missing book — the documented record, an engineer's arithmetic instead of a thriller's villain, and a playbook for the reader who can't fix the system but can stop being the easiest thing in it to drain.
Frequently Asked Questions
Is this a prepper or survivalist book?
No. There is no bunker, no stockpile, and no scenario presented as inevitable. The resilience chapters are about maintenance — password hygiene, financial redundancy, records, and a calm plan for the first hours of a disruption — sized for a normal household or a small business.
Do I need a technical background to read it?
No. Every unavoidable technical term is explained once, in plain English, and there is a working glossary at the back. Practitioners get the synthesis and the systemic framing; everyone else gets the machinery of "the economy" explained by someone who has maintained it.
Does the book say which banks are vulnerable?
No, deliberately. It never asserts that any named institution is insecure or has been breached. The argument runs at the level of system classes — correspondent relationships, treasury platforms, delivery pipelines — because that is where the exposure genuinely lives, and because it is the honest way to make the case.
Will this book be out of date in a year?
Parts of it will, and it says so on the page. It is deliberately timely, anchored to a documented 2025–2026 record that will not change. The framework — attacker as optimization system, exposure in the connective tissue, correlation as the real risk — is built to outlast the news cycle it was written in.
Is AI really carrying out cyberattacks, or is that hype?
It is documented. A frontier lab's own published reporting describes its model executing most of the tactical work in a real campaign, and Taiwan's government confirmed the agent-swarm operation. The book is careful about the other half of the answer too: humans still chose the targets, and overclaiming machine autonomy is exactly the hype it refuses to traffic in.
If You Liked This, You Might Like
- The Bangladesh Bank Heist — the human-speed predecessor of this book's argument: an attack on the financial plumbing, not the vault, back when the attackers still had to sleep.
- Governing at Machine Speed — the regulatory side of the same story, for readers who want to go deeper on the compliance world Chapter 6 can only visit.
- API Driven Banking — the connective tissue of Chapter 8 seen from the builder's side — the people wiring these systems together.
- The MCP Protocol — how AI agents learned to use tools, including the configuration files that became the leak surface Chapter 1 opens on.
The attacker never sleeps now, the money never stops, and the plumbing was never audited — but your own exposure is smaller than the headlines suggest and more fixable than the doomers admit. This book exists to show you exactly where it is.
Included with Kindle Unlimited — read it free if you're a member.
New AI & Technology releases and free chapters — no spam, unsubscribe anytime.



