The cryptocurrency sector is moving towards an AI-driven future, where agents will manage tasks such as travel bookings, trades, and payments. However, recent research suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao forecasting that agents will make a million times more crypto payments than people. A team of security academics and crypto researchers has released a paper highlighting a largely overlooked AI infrastructure vulnerability that can be exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial, found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be compromised if the router is malicious.
The researchers demonstrated that a single compromised router can immediately compromise systems or funds, and that the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials. The implications for crypto users are severe, and the researchers warn of a cascading risk where a single malicious router can compromise the entire system, even if a user trusts their AI provider.