The cryptocurrency sector is on the verge of a significant shift, with AI agents poised to handle a wide range of transactions, from booking flights to executing trades and making payments. However, recent research suggests that the underlying infrastructure supporting this transition may be insecure. According to a report by McKinsey, AI agents could facilitate between $3 trillion and $5 trillion of global consumer commerce by 2030.
Coinbase founder Brian Armstrong has predicted that AI agents will soon outnumber humans in making transactions on the internet, while Binance founder Changpeng Zhao has forecast that agents will make one million times more payments than people, all in crypto. Nevertheless, a group of security academics and crypto researchers have identified a significant vulnerability in the AI infrastructure used in crypto payments. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have released a paper detailing how a largely overlooked component of AI infrastructure can be exploited by malicious actors to steal credentials and drain crypto wallets. The vulnerability lies in so-called 'LLM routers,' which are services that sit between users and AI models, forwarding requests to models like OpenAI or Anthropic.
These routers have full access to all data passing through them, including sensitive information. The researchers found that LLM routers can act as a powerful attack point, allowing malicious actors to intercept and modify sensitive data. This can include private keys, API credentials, and wallet access tokens, which are often transmitted in plain text. The researchers demonstrated how a single malicious router can compromise an entire system, and how easy it is to expand the attack by 'poisoning' parts of the router ecosystem.
The implications for crypto users are severe, as exposed credentials can be copied and reused without the user's knowledge. The researchers have warned that the use of AI agents in crypto payments poses a significant risk, as the underlying infrastructure lacks guarantees that outputs haven't been tampered with.