The cryptocurrency sector is rapidly moving towards a future where AI agents manage various tasks, including transactions and payments, but research suggests that the underlying infrastructure may be vulnerable to security breaches. According to a recent projection by McKinsey, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, while Binance founder Changpeng Zhao forecasts that agents will make millions of times more payments than people, all in crypto.
However, a group of security researchers and academics has released a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that 'LLM routers' or services that connect users to AI models can be exploited by malicious actors.
These routers have full access to all data passing through them, including sensitive information. The researchers noted that LLM agents are increasingly being used for real-world tasks, such as booking flights and managing infrastructure, making them a prime target for attacks. The use of LLM routers leaves users vulnerable, as they assume they are interacting directly with a reputable AI model when, in reality, their requests may be passing through intermediary services that can access and modify their data. According to researcher Chaofan Shou, the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.
The researchers warned that a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.
The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers concluded that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.