The crypto industry is on the cusp of a revolution where AI agents manage various tasks, including payments and trades, but recent research reveals that the underlying infrastructure may be insecure. According to McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao forecasting a massive increase in AI-driven crypto payments.
However, a team of security academics and crypto researchers has discovered a significant flaw in the AI infrastructure that can be exploited to steal credentials and drain crypto wallets. The researchers found that 'LLM routers,' which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors.
These routers have access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be stolen or modified. The researchers demonstrated how a single malicious router can compromise an entire system, and they were able to 'poison' parts of the router ecosystem to gain control over hundreds of downstream systems.
The team warns that the increasing reliance on AI agents in the crypto industry may create a mismatch between the trusted AI providers and the unsecured infrastructure, potentially leading to a cascading risk of compromised systems and funds.