The cryptocurrency sector is rapidly moving towards an AI-driven future, with AI agents expected to manage various tasks, including payments and transactions. According to a recent McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion of global consumer commerce by 2030. However, a recent study has uncovered a significant security flaw in the AI infrastructure that underpins this shift.
A group of security academics and crypto researchers have published a paper highlighting the vulnerability of LLM routers, which are services that connect users to AI models. These routers have the ability to access and modify sensitive data, making them a potential attack point for malicious actors.
The researchers found that LLM routers can be used to steal credentials and even drain crypto wallets, with one instance resulting in a $500,000 loss. The problem is exacerbated by the fact that many users assume they are interacting directly with a reputable AI model, when in reality their requests are passing through intermediary services that can see and modify their data.
The researchers demonstrated how easy it is to exploit this vulnerability, with one test resulting in the exposure of a private key and the draining of a test Ethereum wallet. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers warn that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that could have significant consequences for the cryptocurrency industry.