The cryptocurrency sector is on the cusp of a revolution where AI-powered agents manage various tasks, including payments and transactions. However, recent research reveals that the underlying infrastructure may be insecure, posing significant risks to users.
According to a report by McKinsey, AI agents are expected to facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Industry leaders, such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict that AI agents will soon outnumber humans in making transactions on the internet, with a significant portion of these transactions being crypto-based.
Nevertheless, a group of security researchers and academics from the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial have identified a critical flaw in the AI infrastructure. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors to steal sensitive data, including credentials and private keys.
These routers have unrestricted access to user data, making them a prime target for attackers. The researchers warn that users are extremely vulnerable to these types of attacks, as they often assume they are interacting directly with a reputable AI model. In reality, many requests pass through intermediary services that can intercept and modify sensitive data. One of the researchers, Chaofan Shou, noted that the problem is no longer theoretical, with 26 LLM routers secretly injecting malicious code and stealing credentials, resulting in a $500,000 wallet drain.
The researchers also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The team emphasized that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.