The cryptocurrency sector is rapidly advancing towards an AI-driven future where agents manage various transactions, but recent findings suggest that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict a significant rise in AI agent transactions. However, a group of security academics and crypto researchers have identified a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets.
The researchers, affiliated with the University of California and other institutions, found that 'LLM routers' or services that connect users to AI models can be a powerful attack point for malicious actors. These routers have full access to user data, including sensitive information, and can modify it. The researchers highlighted that LLM agents are taking on real-world financial tasks, making users vulnerable to attacks.
They also noted that the problem is no longer theoretical, with one researcher, Chaofan Shou, revealing that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers demonstrated how a malicious router can replace benign commands with attacker-controlled ones or exfiltrate credentials, compromising systems or funds. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.
The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours.
This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a potential mismatch between the growing use of AI agents in crypto activity and the lack of guarantees that outputs haven't been tampered with.