The rapid growth of AI-powered cryptocurrency transactions has sparked concerns over the security of the underlying infrastructure. According to a recent study, a largely overlooked aspect of AI infrastructure is being exploited by malicious actors to steal sensitive data and drain crypto wallets. Researchers from the University of California and other institutions found that services connecting users to AI models, known as LLM routers, can be used to intercept and modify sensitive information.

These routers, designed to forward requests to AI models like OpenAI, have full access to user data, including private keys, API credentials, and wallet access tokens. The researchers demonstrated how a single malicious router can compromise an entire system, highlighting a weakest-link problem in the AI infrastructure. With industry leaders predicting that AI agents will soon handle a significant portion of crypto activity, the lack of security guarantees in the underlying infrastructure poses a significant risk to users.

The study's findings suggest that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, creating a potential mismatch between the growth of AI-powered crypto transactions and the security of the underlying infrastructure.