The rapid growth of the cryptocurrency industry is expected to be driven by AI agents, which will handle various tasks such as booking flights, executing trades, and making payments. However, a recent research paper suggests that the underlying infrastructure supporting this shift may be insecure.

According to the study, a largely overlooked component of AI infrastructure, known as LLM routers, can be exploited by malicious actors to steal credentials and drain crypto wallets. These routers, which sit between users and AI models, have full access to sensitive data and can act as a powerful attack point. The researchers found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.

The problem is further complicated by the fact that these systems can operate autonomously, approving and executing actions without human review, making them vulnerable to a single altered instruction that can immediately compromise systems or funds. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This highlights a weakest-link problem, where a single malicious router in the chain is enough to compromise the entire system, posing a significant risk to the security of crypto transactions.