The rapid adoption of AI agents in the cryptocurrency industry has raised concerns about the security of the underlying infrastructure. A recent study reveals that a largely overlooked component of AI infrastructure, known as LLM routers, can be exploited by malicious actors to steal sensitive data and drain crypto wallets. These routers, which act as intermediaries between users and AI models, have full access to user data and can modify it without detection. The researchers found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in significant financial losses, including the drainage of a $500,000 wallet.
The study highlights the severe implications for crypto users, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The study underscores the need for increased security measures to protect the underlying infrastructure of AI-powered crypto payments.