The cryptocurrency industry is on the cusp of a revolution, with AI agents poised to handle a wide range of tasks, from flight bookings to trade executions and payments. However, a newly released research paper suggests that the underlying infrastructure supporting this shift may be inherently insecure. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao have both predicted that AI agents will soon outnumber humans in making transactions on the internet, with the latter forecasting that agents will make one million times more payments than people, all in crypto. Nevertheless, a team of security academics and crypto researchers has discovered that a largely overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have identified a critical vulnerability in so-called 'LLM routers,' which act as intermediaries between users and AI models.
These routers, designed to forward requests to models like OpenAI or Anthropic, have full access to all data passing through them, including sensitive information. The researchers found that these routers can be exploited by malicious actors, leaving users extremely vulnerable as they assume they are interacting directly with a reputable AI model.
According to one of the researchers, Chaofan Shou, the problem is no longer theoretical, with 26 LLM routers secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers warn that a single altered instruction can immediately compromise systems or funds, and that private keys, API credentials, and wallet access tokens often pass through these systems in plain text, making them susceptible to exploitation. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
This highlights a weakest-link problem, where a single malicious router in the chain is enough to compromise the entire system, posing a cascading risk to crypto users.