Fintech Conversations & Insights with Efi Pylarinou · 2026-04-29 · 36 min
An autonomous AI agent walked into McKinsey's AI platform - no password, no authentication, no break-in. Within two hours it had access to 46.5 million chat messages, 728,000 files, and 57,000 user accounts. This wasn't a hack in the traditional sense. The agent used permissions it was given. My tweet about this went viral - 500,000 views . The comment that stopped me came from Chris Biele - NFThinker - who builds cryptographic primitives for exactly this problem at Open Matter Network. So I brought him on. In this conversation we go well beyond the McKinsey incident - into what this means for JPMorgan's 200,000-user LLM Suite, why Mastercard and Visa's tokenization approach solves identity but not mandate, how zero-knowledge circuits act as mathematical circuit breakers for rogue agents, and why "harvest now, decrypt later" may be the most underreported threat in finance today. This is the conversation the industry needs to be having before the first major incident inside a bank.