The crypto industry is on the cusp of a revolution where AI agents manage various tasks, including payments and trades, but recent research reveals a potential security vulnerability in the underlying infrastructure. According to a McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, with Binance founder Changpeng Zhao estimating that agents will make a million times more crypto payments than people. However, a group of security researchers has identified a largely overlooked aspect of AI infrastructure that can be exploited to steal credentials and drain crypto wallets.
The researchers, affiliated with the University of California and other institutions, found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have full access to sensitive data, including private keys and API credentials, which can be stolen or modified. The researchers demonstrated that a single malicious router can compromise an entire system, highlighting a weakest-link problem in the infrastructure.
This vulnerability has severe implications for crypto users, as it can lead to the exposure of sensitive information and financial losses. The researchers warn that the increasing reliance on AI agents in crypto transactions may be mismatched with the lack of guarantees that the underlying infrastructure is secure.