The crypto industry is shifting toward an AI-driven future where agents manage various tasks, including transactions and payments, but research indicates that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders like Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict a significant rise in AI agent transactions.
However, a team of security academics and crypto researchers has discovered that a largely overlooked AI infrastructure component is being exploited to steal credentials and drain crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, making users extremely vulnerable.
The problem is no longer theoretical, with one researcher reporting that 26 LLM routers have been secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers warn that a single altered instruction can immediately compromise systems or funds, and the implications for crypto users are severe. They also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
The team emphasizes that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.