The rapid growth of the cryptocurrency industry is driving the adoption of AI agents to manage various transactions, including payments and trades. According to a McKinsey projection, AI agents may facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Industry leaders, such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict a future where AI agents will dominate online transactions, with Zhao estimating that agents will make one million times more payments than people, all in crypto. However, a team of security academics and crypto researchers has identified a critical flaw in the AI infrastructure that underpins these transactions. The researchers found that 'LLM routers,' which act as intermediaries between users and AI models, can be exploited by malicious actors to steal sensitive data, including credentials and private keys. This vulnerability can have severe consequences, including the draining of crypto wallets, as demonstrated by a test case where a router exposed a private key, resulting in the draining of an Ethereum wallet.
The researchers warn that the problem is no longer theoretical, with 26 LLM routers already injecting malicious code and stealing credentials, including a case where a client lost $500,000. The team also demonstrated how a single malicious router can compromise an entire system, creating a cascading risk that threatens the security of the crypto payment ecosystem. As the industry increasingly relies on AI agents to handle transactions, the lack of guarantees that the underlying infrastructure is secure poses a significant threat to users, highlighting the need for urgent attention to address this critical vulnerability.