The crypto industry is on the verge of a significant shift, with AI agents expected to handle a wide range of tasks, from booking flights to making payments. According to a recent projection by McKinsey, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
However, a new study suggests that the infrastructure underlying this shift may be insecure. A group of security researchers and academics have discovered that a largely overlooked component of AI infrastructure, known as LLM routers, can be used to intercept sensitive data and steal credentials.
These routers, which act as intermediaries between users and AI models, have full access to the data passing through them and can be exploited by malicious actors. The researchers found that 26 LLM routers were secretly injecting malicious code and stealing credentials, with one incident resulting in the theft of $500,000 from a client's wallet.
The implications of this vulnerability are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.
As the crypto industry increasingly relies on AI agents, the lack of guarantees that outputs haven't been tampered with poses a significant security risk.