The cryptocurrency sector is rapidly advancing towards an AI-driven future where intelligent agents manage various transactions, but recent findings suggest that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict that AI agents will soon dominate internet transactions, with the latter forecasting that agents will make one million times more payments than humans, all in cryptocurrency.
However, a team of security academics and crypto researchers has discovered that a largely overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that 'LLM routers' or services that connect users to AI models can be powerful attack points for malicious actors.
These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which often pass through these systems in plain text. The researchers demonstrated that a single malicious router can compromise an entire system, highlighting a weakest-link problem. They also showed that it is relatively easy to 'poison' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
The implications for crypto users are severe, as exposed credentials can be copied and reused without the user's knowledge. The researchers warned that the problem is no longer theoretical, citing an instance where a test Ethereum wallet was drained after its private key was exposed. Furthermore, one of the researchers, Chaofan Shou, revealed that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.
The findings suggest a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, creating a potential mismatch as industry leaders increasingly predict AI agents will handle a growing share of crypto activity.