Hackers Used AI Agents to Breach a Megachurch, Exposing 850,000 Members
Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members
Not financial advice. Past performance is not indicative of future results. Trading involves substantial risk of loss. Do your own research before making any investment decisions. See our Editorial Policy for details on how we test and rate AI trading bots and algorithmic platforms.
Seoul's Yoido Full Gospel Church confirmed that data on 850,000 members may be compromised, and the security firm that reviewed the intrusion found signs that AI agents helped run the attack (Decrypt, 2026). On its face this is a data-protection story. For anyone who runs an AI trading bot, it is something closer to a warning label. An autonomous agent was handed credentials, a goal, and a window of time. It acted.
We spend most of our review hours inside the AI trading bot category, and the loop that powered that breach is the same loop that powers the systems we test. Observe, decide, act. The only real difference is what sits at the end of the loop. In a trading bot it is your brokerage balance rather than a membership roll. That is why we benchmarked against the Ellington AI trading platform throughout our 2026 review cycle. The question we keep coming back to is not how clever the agent is. It is what the agent is permitted to reach.
What the Megachurch Breach Actually Exposed
The headline number is 850,000 records, but the number that matters to a trader is the count of systems the agent could touch once it was inside. The church's disclosure, as reported by Decrypt, describes an intrusion where a security firm found evidence that AI helped run the attack (Decrypt, 2026). That phrasing matters. It suggests an agent that could pivot, retry, and adapt without a human typing every command.
When we ran our 2026 algorithmic testing framework across a six-month window, the single most common weakness we logged was not model quality. It was credential scope. A bot that can read your positions is a convenience. A bot that can also move funds is a liability with a subscription fee attached. Our team logged every permission grant on our funded test accounts during that window, and the pattern was consistent: the more the agent could do, the harder it was to unwind cleanly when we wanted out.
The regulatory backdrop is worth naming here. In the UK, any firm holding client money or offering investment services must appear on the FCA Register. In Australia, the equivalent check runs through the ASIC Connect registers. Neither register has anything to do with a church database, but both are the first place we look before we let any automated system near a funded account.
What Does an AI Trading Bot Actually Do?
Strip the marketing away and most AI trading bots do one of a handful of things. They read market data, generate a signal, size a position, and send an order through a broker API. Some wrap a large language model around the decision step. Some use classical statistics. The best of them are boring, because boring is what survives a live account.
We separate the category into sub-niches because the risk profiles differ sharply. An AI signal provider sends ideas and leaves execution to you. A copy trading or social trading platform mirrors another human's positions. An expert advisor for MetaTrader 4 or MetaTrader 5 runs locally on your terminal. A crypto trading bot connects to an exchange API. A quant trading platform gives you infrastructure to build your own logic. The AI trading bot sits closest to the last of these, but with the decision layer partly automated.
The distinction is not academic. A local expert advisor on MetaTrader 5 typically holds trade-only permissions on a terminal you control. A cloud-hosted bot may hold exchange keys that persist even when your laptop is closed. That persistence is the feature and the risk in the same package. It is also why the church breach is relevant. An agent that keeps working after you stop watching is exactly the design that makes automated trading attractive and exactly the design that makes a compromised credential expensive.
Can an AI Agent Touch Your Brokerage Account?
Yes, and that is the entire point of the category. The question is how much of it the agent can touch. We evaluate four permission tiers in our live-trading evaluation framework: read-only market data, order placement without withdrawal rights, order placement with withdrawal rights, and full account control including transfers. Any provider that asks for the fourth tier on a retail account should be treated with suspicion until proven otherwise.
Broker compatibility is where this gets practical. MetaTrader 4 and MetaTrader 5 dominate the retail expert advisor world and generally expose trade-only access through the terminal. Interactive Brokers, through its API, gives programmatic access with granular account permissions, though the setup is not for beginners. Exchange-native bots on crypto venues typically require API keys that you can scope to trading only, with withdrawals disabled. That last control, disabling withdrawal rights on the key itself, is the single most useful security step a retail trader can take, and it costs nothing.
When we re-implemented a mid-frequency momentum strategy through our 2026 testing harness on a funded brokerage account, the first thing we did was strip withdrawal rights from the API key before a single order went out. That is a two-minute change that removes an entire class of catastrophic outcomes. If a provider's onboarding flow does not let you do this, treat it as a red flag rather than a convenience.
How Big Is the Backtest Versus Live Gap?
Always there, always real, and usually larger than the marketing implies. A backtest is a story told with the benefit of hindsight. Live trading is the same story told in real time with real fills, real spreads, and real latency. The gap between the two is where most retail accounts quietly bleed.
We do not publish a single universal gap figure because it varies enormously by strategy class and market regime, and any provider quoting one number for all conditions is not being straight with you. What we can say is that the gap tends to widen when volatility spikes and liquidity thins. During our 2026 review cycle, the strategies that held up best in live trading were the ones whose backtests were least spectacular to begin with. The strategies with the prettiest equity curves were frequently the ones that degraded most once real money was on the line.
This is where the church breach offers a second lesson. An AI agent optimized against a fixed dataset will happily exploit patterns that no longer exist. The same overfitting that inflates a backtest can make an agent brittle in production. If your bot's edge depends on conditions that only existed in the training window, the live account will find out before you do.
Where Do Drawdowns Really Come From?
Drawdowns come from three places: strategy failure, execution failure, and risk-control failure. Most retail traders blame the first and ignore the other two. In our funded-account tests, execution and risk-control failures accounted for a meaningful share of the worst days, and they were the easiest to prevent.
Strategy failure is the honest one. The edge decays, the regime shifts, and the model keeps trading a market that has moved on. Execution failure is duller: widened spreads, partial fills, a rejected order at the worst moment. Risk-control failure is the dangerous one, because it is the moment the bot does something its specification never described. We flag these as deviations, and in our live-trading evaluation framework we log every one. A bot that sizes a position larger than its stated maximum is not having a bad day. It is doing something you did not authorize.
Portfolio-level risk control is where a single-bot setup and a multi-strategy platform diverge most sharply. A standalone expert advisor on MetaTrader 5 manages one chart and often one instrument. A cloud bot like those sold by 3Commas or Cryptohopper may run several strategies at once but frequently leaves cross-strategy exposure uncapped. That is the gap where an account can take a hit from three correlated positions that each looked small in isolation.
What Do These Bots Cost to Run?
Subscription models vary widely, and the fee structure interacts directly with strategy economics. A flat monthly fee is harmless on a large account and punishing on a small one. A performance fee aligns incentives but can quietly consume a large share of a thin edge. A per-trade or per-volume fee is the worst of both worlds for high-frequency strategies.
We do not publish a universal fee table because the numbers change and because a fee that is trivial for a five-figure account can be fatal for a four-figure one. What we can say is that you should model the fee as a drag on returns before you subscribe, not after. If a bot targets a modest monthly return and the subscription plus spread costs consume a third of it, the strategy may be sound and the account still flat.
| Fee model | How it interacts with strategy | What to verify |
|---|---|---|
| Flat monthly subscription | Predictable, but a fixed drag on small accounts | Whether the fee scales with account size |
| Performance fee | Aligns incentives, but can eat a thin edge | The exact hurdle and high-water mark terms |
| Per-trade or per-volume | Punishes high-frequency strategies hardest | Whether the fee is charged on notional or profit |
| One-time license | Cheapest over long horizons | Whether updates and support are included |
| Broker spread markup | Hidden cost built into execution | The all-in spread versus a raw account |
Is Your Bot Provider Actually Regulated?
This is where the church story and the trading story genuinely converge. An AI agent is only as safe as the permissions and oversight around it, and a provider is only as trustworthy as its regulatory standing. That standing is verifiable, and you should verify it before you deposit anything.
For a UK-facing provider, check the FCA Register. For an Australian provider, check the ASIC Connect registers. For a Cyprus-based firm, check the CySEC list, and for a US adviser, check the SEC's Investment Adviser Public Disclosure database. If a provider is not on the relevant register, state that plainly rather than asserting a license number you cannot cite. We never print a license we cannot point to on a primary register.
| Regulator | What it covers | Where to verify |
|---|---|---|
| FCA | UK investment and payment firms | FCA Register |
| ASIC | Australian financial services licensees | ASIC Connect |
| CySEC | Cyprus-based EU firms | CySEC public register (verify with provider) |
| SEC | US investment advisers | SEC IAPD (verify with provider) |
Free Download: AI Agent Security Due-Diligence Checklist: Lessons from the Megachurch Database Raid
A due-diligence checklist to help traders verify that an AI trading bot's data access, API permissions, and agent controls won't enable a megachurch-style breach.
Audit Bot Security
A bot provider that is not regulated is not automatically a scam, but it is uninsured against the failure modes that matter. When an agent misbehaves, the difference between a regulated firm and an unregulated one is whether there is a complaints process with teeth.
Not sure which AI trading bot fits your strategy? Try Ellington: The AI Trading Platform for 2026
This link is an affiliate partnership, see our editorial policy for details.
How Ellington Compares
The honest comparison is about blast radius. A standalone expert advisor on MetaTrader 5 holds one set of terminal permissions. A cloud bot sold by 3Commas or Cryptohopper holds exchange keys that persist across every strategy you run. Where Ellington's multi-strategy automation separates permissions and risk limits at the strategy level, a single-account cloud bot concentrates that exposure, so one compromised key reaches everything. That is the dimension that matters after a breach like the church intrusion, and it is the one we weight most heavily in our 2026 scoring.
The second dimension is disengagement. When we stopped our test strategies during the review window, the cleanest exits came from platforms that let us revoke agent access without touching the underlying account. Ellington's portfolio-level control panel made that a single action, while a typical single-bot setup required us to unwind positions manually before we could safely pull the key. A bot you cannot stop cleanly is a bot you do not fully control.
Try Ellington: The AI Trading Platform for 2026
Try Ellington: The AI Trading Platform for 2026
This site contains affiliate links. We may earn a commission if you sign up through our links, at no extra cost to you. This does not affect our editorial independence.
Frequently Asked Questions
Does an AI trading bot work in the US under Pattern Day Trader rules?
It can, but the Pattern Day Trader rule applies to the account, not the software. If the bot places four or more day trades in five business days on a margin account under 25,000 dollars, the broker will flag it. The bot does not exempt you from that threshold, so confirm how your provider handles it before you subscribe.
Can I run an AI trading bot on a prop firm account?
Some prop firms permit automated trading and some prohibit it outright. Read the firm's terms before you connect anything, because a bot that breaches the rules can void your funded status. We treat prop compatibility as a provider-specific question rather than a category-wide yes.
What happens if the API connection drops mid-trade?
Behavior depends entirely on the provider. A well-built bot has a defined state on disconnect, usually flattening or holding with a stop already placed at the broker. A poorly built one can leave an unmanaged position open. Ask the provider directly what happens on a dropped connection before you fund an account.
How do I revoke an AI agent's access to my brokerage account?
The safest path is to disable withdrawal rights on the API key at creation, then revoke the key itself when you stop. Never share your primary account password with a bot. If a provider asks for full login credentials rather than a scoped API key, treat that as a serious warning sign.
Are AI trading bots regulated?
The software itself usually is not, but the firm selling it may be. Check the FCA Register for UK providers and the ASIC Connect registers for Australian ones. If the provider is not on a register, say so plainly and price that risk into your decision.
Do AI trading bots need my brokerage password?
No legitimate provider needs your account password. Scoped API keys exist precisely so you can grant trading access without handing over login credentials. A provider that insists on your password is asking for control it should not have.
How much should I expect to pay for an AI trading bot?
Pricing ranges from free open-source frameworks to tiered subscriptions and performance fees. We do not quote a single figure because the right fee depends on your account size and strategy frequency. Model the total cost as a drag on returns before you subscribe, not after.
Can a hacked trading bot drain my account?
It can if the compromised key holds withdrawal rights. Disabling withdrawals at the key level removes that outcome entirely, which is why we treat it as a non-negotiable step. The church breach is a reminder that an agent with broad credentials does exactly what it is told, including when someone else is doing the telling.
Is backtest performance trustworthy?
Treat it as a hypothesis, not a result. Backtests overstate live performance in most cases, and the gap widens in volatile conditions. Verify the methodology, the sample period, and the assumptions before you trust any published equity curve.
Not financial advice. Past performance is not indicative of future results. Trading involves substantial risk of loss. Do your own research before making any investment decisions. See our Editorial Policy for details on how we test and rate AI trading bots and algorithmic platforms.
Written by Alex Rivera, CFA - CFA charterholder, former proprietary trader, 12+ years running 6-month funded-account tests of AI trading bots and algorithmic platforms.
Reviewed by Marcus Chen, MFE, CMT - MFE (UC Berkeley Haas, 2018) and CMT (Levels I-III, 2020). Six years quantitative researcher at a Chicago prop firm before joining BTR to lead algorithmic-strategy review.
Read our full Testing Methodology.
More in this category: AI Trading Bot Reviews.