The cryptocurrency sector is rapidly advancing towards an era where AI agents will manage various tasks, including transactions and payments. However, recent research suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao forecasting that agents will make millions of times more payments than people, all in crypto. A group of security academics and crypto researchers have published a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure, which has already been linked to stolen credentials and a $500,000 wallet drain. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, identified 'LLM routers' as a critical vulnerability.
These services, designed to forward requests to AI models like OpenAI or Anthropic, have full access to sensitive data and can be exploited by malicious actors. The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain. They also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The team warned that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.