The rapid evolution of the cryptocurrency industry is driving towards a future where AI agents manage various tasks, including transactions and payments. However, recent findings suggest that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make a million times more payments than people, all in crypto. A group of security academics and crypto researchers has released a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure.
The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that 'LLM routers' or services that connect users to AI models can be exploited by malicious actors. These routers have full access to sensitive data, including credentials and financial information. The team discovered that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain. The researchers warn that a single malicious router can compromise entire systems or funds, and the autonomous nature of these systems allows for frequent approvals and executions without human review.
For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers emphasize that a single malicious router in the chain is enough to compromise the entire system, creating a weakest-link problem.
This raises concerns about the trustworthiness of the infrastructure, even if a user trusts their AI provider. As industry leaders predict AI agents will handle a growing share of crypto activity, the underlying infrastructure still lacks guarantees that outputs haven’t been tampered with.