The crypto industry is on the cusp of a revolution where AI agents manage various transactions, but research suggests the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make a million times more crypto payments than people. However, a group of security academics and crypto researchers have identified a vulnerable component of AI infrastructure that can be exploited to steal credentials and drain crypto wallets.
The researchers, affiliated with the University of California and blockchain firm Fuzzland, found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be stolen or modified. The researchers demonstrated that a single malicious router can compromise an entire system, and by poisoning parts of the router ecosystem, they were able to observe and control hundreds of downstream systems within hours.
This highlights a weakest-link problem, where the security of the entire system relies on the trustworthiness of each individual router. The implications for crypto users are severe, as exposed credentials can be reused without their knowledge, and the researchers found multiple cases where routers collected sensitive information.
The team's findings suggest that the growing reliance on AI agents in crypto transactions may be premature, given the lack of guarantees that the underlying infrastructure is secure.