The rapid growth of the cryptocurrency industry is driving the adoption of AI agents to manage various tasks, including transactions and payments. However, a recent study reveals that the underlying infrastructure supporting this shift may be insecure. According to projections by McKinsey, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict that AI agents will soon surpass humans in making transactions on the internet, with a significant portion of these transactions being crypto-based.
Nevertheless, a group of security academics and crypto researchers have identified a critical flaw in the AI infrastructure that could be exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that 'LLM routers' – services that act as intermediaries between users and AI models – can be used as a powerful attack point by malicious actors.
These routers have full access to sensitive data, including credentials and wallet information, and can modify or steal this data without the user's knowledge. The researchers highlight that the problem is no longer theoretical, with one researcher, Chaofan Shou, reporting that 26 LLM routers have been found to be secretly injecting malicious code and stealing credentials, resulting in a $500,000 wallet drain.
The implications of this vulnerability are severe, particularly for crypto users, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a weakest-link problem.
As industry leaders increasingly predict that AI agents will handle a growing share of crypto activity, the underlying infrastructure still lacks guarantees that outputs haven’t been tampered with, creating a potential mismatch.