The rapid growth of AI agents in the cryptocurrency industry has sparked concerns over the security of the underlying infrastructure. According to recent projections by McKinsey, AI agents may mediate between $3 trillion and $5 trillion of global consumer commerce by 2030. However, a group of security academics and crypto researchers have identified a potential flaw in the system, which could allow malicious actors to intercept sensitive data and steal credentials.
The researchers found that so-called 'LLM routers,' which act as intermediaries between users and AI models, can be used to exploit sensitive information. These routers have full access to all data passing through them, including private keys, API credentials, and wallet access tokens.
The researchers demonstrated how a single malicious router can compromise an entire system, highlighting the need for greater security measures to protect users' sensitive information. With industry leaders predicting that AI agents will handle an increasing share of crypto activity, the lack of guarantees that outputs haven't been tampered with poses a significant risk to users.
The researchers' findings suggest that the current infrastructure may not be secure enough to support the widespread adoption of AI-powered crypto payments.