The cryptocurrency industry is rapidly advancing towards a future where AI-powered agents manage various tasks, including transactions and payments. However, recent research suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon surpass human transactions on the internet, while Binance founder Changpeng Zhao forecasts that agents will make one million times more payments than people, all in crypto.
Nevertheless, a group of security academics and crypto researchers have identified a largely overlooked AI infrastructure flaw that can be exploited to steal credentials and drain crypto wallets. The researchers discovered that LLM routers, which act as intermediaries between users and AI models, can be used as powerful attack points by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and modified.
The researchers found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. This creates a cascading risk, where a single malicious router in the chain can compromise the entire system, highlighting a weakest-link problem in the AI infrastructure.