The rapid growth of AI-powered transactions in the cryptocurrency industry is expected to revolutionize the way payments are made, with estimates suggesting that AI agents could facilitate $3 trillion to $5 trillion of global consumer commerce by 2030. However, a recent study reveals a significant security flaw in the infrastructure underpinning this shift, which could expose wallets and compromise sensitive data. A group of security academics and crypto researchers have identified a largely overlooked piece of AI infrastructure, known as LLM routers, which can be exploited by malicious actors to steal credentials and drain crypto wallets. These routers, designed to forward requests to AI models, have full access to sensitive data and can act as a powerful attack point.

The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain. The implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text, leaving users vulnerable to attack. The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.

This creates a cascading risk, where a single malicious router in the chain can compromise the entire system, highlighting the need for increased security measures to protect users and prevent potential losses.