MoonPay Lets ChatGPT, Claude Move Crypto, Prompting Warnings of AI's Growing Risk to Sector

29 July 2026 - 19:10 UTC
By Jona Jaupi
MoonPay logo
Sandmark

MoonPay is handing artificial intelligence the ability to move real money – and betting that users will trust it to know when, where and how to spend it. Some experts say it's a wager that users may come to regret.

The crypto payments company on 29 Jul launched PayBox, an AI payment vault that lets users of the popular AI chat assistants, ChatGPT and Claude, to make crypto transactions and payments using natural language. Users can approve each transaction with a passkey or allow the AI to act within preset limits across Solana and Ethereum Virtual Machine-compatible networks, including Ethereum, Base, Arbitrum and Polygon.

But as companies race to turn AI assistants into autonomous financial actors, cybersecurity experts warn that the biggest threat may no longer be protecting crypto wallets but preventing AI from making the wrong financial decisions.

From assistant to actor

The new feature allow users to ask the AI to buy stablecoins, swap tokens, move crypto between blockchains, use decentralized finance (DeFi) apps or make payments. "Users should think of these agents like a chief of staff," Neeraj Prasad, chief engineer at MoonPay Labs, told Sandmark. "The agents are given permission by the user to take actions, and the more autonomy a user gives their agent, the more tasks the agent removes the need to do manually."

The launch comes as companies race to build AI agents that can complete tasks on users' behalf. Exchange operator Coinbase has introduced agentic wallets, while stablecoin issuer Circle, Visa and Mastercard have also announced AI payment initiatives aimed at helping AI agents move money. Gartner expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from just under 5% in 2025. 

Viktor Bulanek, founder and chief technology officer of cybersecurity firm Penetrify, said that while allowing AI to execute financial transactions marks an important step for agentic AI, it also creates a new security challenge. 

"Letting an LLM move real money is the moment agentic AI stops being a demo," Bulanek told Sandmark." That's genuinely a milestone. It's also exactly why it makes me nervous." LLMs, or large language models, refer to the AI system behind chatbots such as OpenAI's ChatGPT and Anthropic's Claude.

AI's decision-making, not wallets, is the biggest risk

Bulanek said his biggest concern is no longer the security of crypto wallets, but the AI systems deciding where money should go. "The biggest risk isn't the crypto part, that's the well-understood half," he said. "The new hole is the agent's decision layer."

He said attackers could use prompt injection – or hidden malicious instructions – to trick an AI agent into sending funds to the wrong address. And because blockchain transactions tend to be permanent, getting back stolen funds could prove difficult – if not impossible.

"Your agent reads some untrusted data, a webpage, a token listing, a message, and buried in it are instructions that steer it into initiating a payment to an attacker," he explained. "Same trick we've had for a while, except now the payload is money and the transaction is irreversible – crypto has the worst possible blast radius for this, because there's no chargeback."

MoonPay said users can choose how much control to retain over transactions, including requiring approval each time the AI attempts to move funds. "We ensure there is a clear boundary between user and agent capabilities in PayBox with our approval mode," Prasad said. "Every time an agent submits a transaction, the user receives a pop-up asking to approve or deny."

However, Penetrify's Bulanek questioned whether transaction-by-transaction approval would provide a reliable safeguard in practice. "Agentic UX trains people to rubber-stamp approvals, that's approval fatigue, and a well-crafted injection makes the malicious payment look like the one you actually meant to make at the exact moment you're clicking yes," he said. "So approval is not the backstop people treat it as."

He added that while technologies such as multi-party computation (MPC), trusted execution environments (TEEs) and passkeys help protect private keys and user accounts, they cannot stop an AI agent from making a bad decision. "You've locked the vault and handed the combination to something that can be socially engineered," Bulanek said. 

AI Agents, moving forward

Joshua Copeland, director of cybersecurity at Crescendo AI and professor at Tulane University, said PayBox is part of a broader shift from AI recommending transactions to actually carrying them out. "That is the line between an assistant and a financial actor," he told Sandmark.

However, he explained that he expects the market to move towards "graduated autonomy" rather than unlimited autonomy. "Low-risk, repetitive and inexpensive transactions may occur automatically," Copeland said. "Medium-risk transactions may trigger notifications, while high-value or unusual payments will require explicit confirmation through a separate trusted channel."

Copeland added that companies are also already looking at ways to confirm not only who approved a payment, but also whether the payment matched what the user intended. "The winning platforms will not be those that give the agent the most freedom," he said. "They will be the ones that make delegated authority observable, constrained and recoverable."

The Tulane professor also predicts that AI payment tools will bring stablecoins – digital assets that are designed to maintain a steady value by being pegged to fiat currency – to more people by making crypto easier to use. Stablecoins currently boast a market capitalization of over $308bn, according to DeFiLlama data. 

"If using an AI payment vault still feels like managing crypto, adoption will remain limited," Copeland said. "If it feels like telling a trusted assistant to complete a purchase, stablecoins could become infrastructure that millions of people use without ever thinking of themselves as crypto users." 

Add as a preferred source on Google