The math didn’t add up at first glance. A blockchain media outlet, citing an unknown source named “Dongcha Beating,” reported that OpenAI’s Codex and ChatGPT Work agents have hit 10 million weekly active users. The numbers are too clean. A 1,025% quarterly growth. A “milestone” reward system tied to user counts. It reads like a pitch deck, not a product update. But even if the data is accurate, the real story isn’t the growth curve—it’s the structural fragility that comes with it.
Context: The Agent Hype Cycle OpenAI has pivoted hard from model provider to agent platform. Codex is a “coding agent.” ChatGPT Work is an “office agent.” Both are designed to execute tasks autonomously within user workflows. The company set a public challenge: unlock usage limits for every 1 million user milestone, up to 10 million. It’s a textbook growth-hack. But the narrative is missing critical details: no technical audit of agent capabilities, no security breach history, no cost-per-token breakdown. The industry is celebrating a user metric as if it validates the entire agent paradigm. It doesn’t. It validates the marketing.
Core: Systemic Risk in Centralized Agents Let’s strip away the hype. 10 million weekly active users means 10 million live connections to a single AI infrastructure. Each connection is a potential vector for prompt injection, data exfiltration, or catastrophic hallucination. In my audit of the Harvest Finance exploit—a $30 million loss due to missing pause mechanisms—I saw the same pattern: trust in a single point of failure.
Security isn’t the foundation. It’s an afterthought. OpenAI’s agents have no verifiable on-chain governance. No decentralized oversight. No emergency stop that doesn’t rely on a human pulling a plug. If a malicious prompt causes ChatGPT Work to delete a corporate document repository, who pays? The answer is the enterprise that delegated its workflow to a black box.
Hype burns out; structural integrity remains. The cost of inference for 10 million users is staggering. Assume each user generates 1,000 tokens per active session. Weekly token consumption exceeds 10 trillion. At current H100 pricing, that’s millions of dollars per week in energy and hardware wear. OpenAI’s margin depends on algorithmic improvements that have not been disclosed. If the cost-per-token floors, the unit economics collapse. The “free tier” expansion becomes a burning platform.
Speculation masks the absence of utility. The utility of an AI agent is only as good as its worst failure case. A coding agent that writes insecure code is worse than no agent. An office agent that misreads a meeting request and schedules a CEO’s flight to the wrong continent is a liability. The industry hasn’t standardized agent safety benchmarks. Every rug has a seam you missed. In crypto, we learned this the hard way across $2.5 billion in bridge hacks. AI agents are the new bridges—centralized, opaque, and one exploit away from destroying trust.
Contrarian: What Bulls Got Right To be fair, the user growth is impressive. It demonstrates product-market fit in a segment many doubted. The data flywheel is real: more users generate more feedback, which improves model outputs. OpenAI’s vertical integration from model to app is a strategic moat. Competitors like Anthropic and Google lack an equivalent agent product with this scale. The milestone tactic also proves that usage-based rewards drive engagement. These are tangible wins.
But the bulls ignore the fragility. A centralized flywheel can jam with a single gear failure. The same data that improves the model also entrenches user dependency. Switching costs rise, but so does systemic risk. The question isn’t whether the agent works today. It’s whether the mechanism can survive a major incident. History says no.
Takeaway: Forward-Looking Judgement The 10 million user milestone is a signal of market dominance, but also a beacon for regulators and attackers. The blockchain origins of this report should make every crypto native cautious: we know whose numbers to trust, and these aren’t audited. The next breakthrough in AI won’t be a smarter model. It will be a verifiable, decentralized agent ecosystem that can fail gracefully. Until then, every centralized agent is a ticking time bomb. Prepare for the cascade.