The cryptocurrency industry is on the cusp of a revolution, with AI agents poised to manage a wide range of tasks, from flight bookings to trade executions and payments. However, a new research paper suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make one million times more payments than people, all in crypto. Nevertheless, a group of security academics and crypto researchers have identified a critical vulnerability in the AI infrastructure, which has already been exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that 'LLM routers' or services that connect users to AI models can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which are often transmitted in plain text.
The researchers found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in significant financial losses. They also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The study highlights the cascading risks associated with the use of AI agents in crypto payments, where a single malicious router in the chain can compromise the entire system.
This raises concerns about the security of the underlying infrastructure, which may not provide guarantees that outputs haven't been tampered with, even if a user trusts their AI provider.