The crypto industry is on the cusp of a revolution where AI agents manage various tasks, including payments and trades. However, recent research reveals that the underlying infrastructure may be insecure. According to a report by McKinsey, AI agents are projected to handle between $3 trillion and $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao forecasting that agents will make one million times more payments than people, all in crypto. A group of security academics and crypto researchers has released a paper highlighting a largely overlooked piece of AI infrastructure that is being exploited to steal credentials and drain crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors.
These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which are often transmitted in plain text. The researchers demonstrated how a single malicious router can compromise an entire system, underscoring the need for increased security measures to protect crypto users.
The implications are severe, as exposed credentials can be copied and reused without the user's knowledge, allowing attackers to drain wallets and steal funds. The researchers warn that the lack of guarantees about the integrity of AI infrastructure outputs poses a significant risk to the crypto industry, which is increasingly relying on AI agents to handle sensitive transactions.