How VitaminAi’s security architecture shows why AI/Web3 commerce needs a new approach to identity, fraud prevention, privacy and escrow protection
AI agents are beginning to move from assistants into commercial infrastructure. They can recommend products, match buyers and sellers, analyse audiences, select creators, automate campaign workflows and support transaction decisions.
That shift creates a new cybersecurity problem. Traditional security models were built around human users, enterprise applications, cloud infrastructure, networks and endpoints. AI-agent marketplaces create a more complex environment: autonomous software actors, Web3 wallets, pseudonymous identities, smart-contract settlement, creator reputation, campaign fraud, on-chain activity and adversarial AI behaviour all interacting inside the same product.
This is no longer an edge-case problem. The same trust challenge is emerging across the UK, US and EU as AI becomes embedded into commerce, financial workflows, creator platforms and digital-marketplace infrastructure. In the UK, the pressure is visible in the broader cyber landscape. The government’s 2025 cyber security labour-market report estimated around 143,000 people in the UK cyber security workforce and a workforce gap of around 3,800 people. (GOV.UK) The UK’s 2025/26 Cyber Security Breaches Survey also found that 43% of businesses and 28% of charities had identified a cyber breach or attack in the previous 12 months. (GOV.UK)
The challenge is becoming more specialised. AI/Web3 marketplaces need professionals who understand cyber security, AI assurance, Web3 fraud, privacy engineering, product architecture and commercial adoption at the same time.
One company working directly on this problem is VitaminAi, a London-based AI Agent Marketplace for Web3 marketing. The platform connects brands, AI agents and Web3 creators through campaign discovery, booking, analytics and escrow-backed settlement. In this kind of marketplace, trust is part of the product itself. If brands cannot verify participants, assess wallet risk, detect fraudulent behaviour or trust the settlement layer, the platform cannot credibly support enterprise campaigns.
A key figure behind this trust architecture is Ibtihajul Islam, Cyber Security Product Architect at VitaminAi.
Why existing security tools are incomplete
The cyber security industry already has strong tools for many parts of the problem. Identity and access management can control users. Zero-trust architecture can reduce implicit trust across services. Blockchain analytics can flag suspicious wallets. Smart-contract audits can review settlement logic. Fraud systems can score transactions. LLM red-teaming can test model behaviour.

The limitation is that these tools usually operate in separate layers.
A wallet-risk tool may not understand campaign context. A smart-contract audit may not understand AI-agent behaviour. A zero-trust gateway may not understand Web3 identity. A fraud model may not reason across creators, wallets, campaigns, chains and agent behaviour together. Manual moderation may work at small scale, but it becomes weak when marketplace activity is automated, cross-chain and high volume.
AI-agent marketplaces need a more integrated trust layer. The product has to decide, in real time, whether an agent, creator, wallet, campaign or escrow event should be trusted. That decision cannot sit only inside a compliance workflow. It has to sit inside discovery, booking, ranking, approval, settlement and reporting.
This is the architecture problem VitaminAi has been trying to solve.
VitaminAi’s approach: trust as product infrastructure
VitaminAi’s marketplace model brings together brands, creators, AI agents, wallets, campaign performance data and escrow-backed settlement. That makes the platform commercially powerful, but also technically exposed.
A creator may be linked to multiple wallets. Campaign behaviour may cross several chains. Engagement signals may be manipulated. An AI agent may be targeted through prompt injection or goal hijacking. A settlement workflow may become a financial attack surface. A privacy layer has to protect sensitive user and campaign data while still giving enterprise customers useful analytics.
According to company materials, VitaminAi’s answer has been to build security directly into the platform’s product architecture. The security layer covers six main systems:
- a zero-trust access gateway for agents and services;
- a graph-based trust fabric for agents, wallets, creators and campaigns;
- an on-chain risk and reputation engine for sybil and wash-trading detection;
- a secure escrow and settlement architecture;
- a privacy-preserving analytics layer;
- and an adversarial red-teaming framework for AI-agent behaviour.
The technical importance lies in the combination. Zero trust, graph reasoning, formal verification, differential privacy and adversarial testing are recognised areas of cyber security and computer science. VitaminAi’s architecture applies them together to a live AI/Web3 marketplace, where autonomous agents, wallet identities and financial settlement interact inside one commercial product.
From research to prototype to production
Ibtihajul’s role becomes important at this point. His contribution was not simply to apply a checklist of existing controls. According to VitaminAi materials, he designed the platform’s trust, access-control, on-chain fraud-prevention, privacy, escrow and AI-agent testing architecture as product capabilities.
His route into this work followed a research-to-product path.

Before the systems became VitaminAi platform infrastructure, the underlying ideas were developed through applied research in zero-trust AI ecosystems, Graph-RAG trust reasoning, cross-chain anomaly scoring, secure escrow design, blockchain-based PKI and privacy-preserving computation. Ibtihajul’s publication record includes papers on a Zero-Trust Agent Gateway for multi-actor AI ecosystems, an Agent Trust Fabric using Graph-RAG risk reasoning, an on-chain reputation and anomaly-scoring engine, and a secure escrow and settlement architecture for Web3 marketing campaigns. His CV also records earlier research work on blockchain-based PKI using linkable ring signatures and outsourced k-means clustering using fully homomorphic encryption.
The practical significance is that these ideas did not remain research concepts. They moved into prototype architecture, threat modelling, system design and then production deployment inside VitaminAi.
That sequence matters. AI/Web3 marketplaces do not need theoretical cyber security alone. They need architectures that can survive real user activity, real wallets, real campaign budgets, real enterprise reviews and real adversarial behaviour.
Problem 1: Can autonomous agents be trusted?
One of VitaminAi’s core security problems is agent and creator trust. A marketplace needs to know whether an AI agent, a creator identity, a wallet and a campaign history are behaving consistently. It also needs to identify relationships that may indicate manipulation, compromise or recycled fraud.

Ibtihajul’s Agent Trust Fabric addresses this through a knowledge graph linking AI agents, creator profiles, wallets, campaigns, chains and behavioural histories. A Graph-RAG layer then performs multi-hop reasoning across those relationships and produces explainable trust signals that can feed into campaign approvals and escrow gating.
This moves beyond static scoring. In a conventional marketplace, a risk score may sit against one user or one transaction. In an AI/Web3 marketplace, the risk may sit in the relationship between an agent, a wallet cluster, a campaign pattern and a creator identity.
According to company materials, the Agent Trust Fabric contributed to a 30% reduction in suspicious campaigns reaching the booking stage and a 23% increase in campaign renewal and upsell revenue.
Problem 2: Can wallet-linked marketplace activity be made fraud-resistant?
Web3 marketplaces also face wallet-based fraud. Sybil networks, wash trading, risky-address relationships and cross-chain provenance laundering can distort trust signals. A marketplace may see a creator profile, while the real risk sits in wallet history, cross-chain movement or hidden clusters.
Ibtihajul’s Cross-EVM Risk and Reputation Engine normalises wallet and transaction activity across Ethereum, Polygon, Arbitrum, Base and Solana. It uses transaction graph topology, temporal patterns and cross-chain provenance tracing to detect sybil clusters and wash-trading rings. The risk scores then feed directly into marketplace discovery ranking and escrow eligibility.
The product point is important. The system does not only produce an analyst report. It operationalises risk into marketplace decisions. A risky wallet or creator relationship can affect whether a campaign reaches booking, whether a creator appears in discovery or whether escrow eligibility is approved.
VitaminAi materials attribute a 55 to 60% reduction in campaign-level fraud and payment disputes to this risk architecture, with sybil detection measured at F1 0.88 and wash-trade detection at F1 0.83.
Problem 3: Can money move safely through AI/Web3 campaigns?
Escrow is one of the most sensitive parts of any marketplace. In Web3 environments, escrow risk becomes more visible because funds, wallet interactions and smart-contract behaviour can all become attack surfaces.
Ibtihajul’s Secure Escrow and Settlement Architecture was designed around tiered multi-signature approvals, cryptographic role segregation between brand, agent and platform actors, and an eight-state finite-state machine modelled in TLA+. The purpose is to make fund release dependent on explicit, auditable transitions rather than informal operational judgement.
According to company materials, the escrow architecture supports more than USD 900,000 in annual GMV and has recorded zero escrow failures or unauthorised fund releases during the reviewed deployment period.
For enterprise customers, this kind of architecture matters because transaction integrity becomes part of procurement confidence. A brand committing campaign budgets through an AI/Web3 marketplace needs to know how funds are held, released, disputed and protected.
Problem 4: Can AI agents be tested before they affect transactions?
AI-agent systems also need a different red-teaming model. Traditional penetration testing remains useful, but it does not fully address prompt injection, goal hijacking, cross-agent collusion or manipulation of AI-driven decision logic.
Ibtihajul’s adversarial testing framework focuses on these agent-specific scenarios. It tests prompt injection against campaign approval flows, goal hijacking against escrow-release logic, cross-agent collusion, and on-chain replay or front-running patterns. According to company materials, this testing identified and remediated six critical vulnerabilities before production deployment across key platform systems.
This is an important direction for the sector. As AI agents take on more commercial functions, red-teaming has to examine how agents interact with money, identity, marketplace rules and transaction workflows.
The commercial value of trust-by-design
The strongest product security work has a commercial effect. It can reduce fraud exposure, shorten security reviews, improve enterprise confidence and make higher-value transactions easier to approve.
According to VitaminAi materials, the Zero-Trust Agent Gateway blocks more than 32,000 malicious or suspicious requests per month, with zero critical security incidents affecting customer funds or personal data during the reviewed period. The same materials state that enterprise customers with annual platform budgets above USD 100,000 cited the security architecture during technical due diligence.
The platform-impact evidence also records 817,606 users served, 25,000 creators onboarded, 145 brand partnerships, and partnerships with Binance, Ledger, Coinstore and Token 2049. These are company-level outcomes, rather than achievements attributable to one architect alone. The relevant point is more specific: VitaminAi attributes its trust, fraud-prevention, escrow and security-readiness layer to the architecture Ibtihajul designed and delivered.
That distinction is important. A cyber security architect does not create every user, every brand partnership or every commercial campaign. The value of the architecture lies in making a new category of product safe enough for enterprise adoption.
Why the UK, US and EU should care
The trust problem facing VitaminAi is part of a wider shift in digital commerce. AI agents are entering workflows in marketing, fintech, customer service, creator platforms, software procurement, content operations and marketplace discovery. In the US and EU, the same pattern is visible: platforms are becoming more automated, more data-rich and more dependent on trusted digital identity and secure transaction flows.
In the UK, this intersects with a wider policy and market concern around cyber capability. GOV.UK lists cyber security and artificial intelligence among the digital technology fields relevant to the Global Talent route. (GOV.UK) The UK cyber security labour market report also highlights a continuing workforce gap, while European agencies continue to focus on cyber skills and competence as a strategic issue for digital resilience. (GOV.UK) (ENISA)
The next shortage may be even more specific than cyber security in general. AI/Web3 platforms need people who can combine secure system architecture, adversarial AI testing, privacy engineering, cryptographic thinking, wallet-risk intelligence and product-commercial understanding.
That is the category Ibtihajul’s work represents.
The next frontier: security architects for agentic commerce
AI-agent marketplaces will need to answer a simple question before they can scale: can the platform prove why its agents, wallets, creators, campaigns and settlement flows should be trusted?
That proof will require more than perimeter defence. It will require identity-centric access, graph-based risk reasoning, on-chain fraud detection, privacy-preserving analytics, auditable escrow logic and adversarial testing built into the product itself.
VitaminAi’s architecture is one example of how this can be done. Ibtihajul’s contribution shows the path from applied research, to prototype architecture, to production product infrastructure. It also illustrates a broader direction for the sector: cyber security moving from control layer to commercial trust layer.
As AI agents become more capable and digital platforms become more autonomous, the professionals who can build that trust layer will become increasingly important. For AI/Web3 commerce, trust will be a technical architecture, a customer-confidence requirement and a commercial growth condition at the same time.



