The crypto industry is on the cusp of a revolution, with AI agents poised to manage everything from travel bookings to financial transactions. However, a new study reveals that the underlying infrastructure may be vulnerable to attack. According to a report by McKinsey, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, with Binance founder Changpeng Zhao forecasting that agents will make a million times more crypto payments than people.
Nevertheless, a team of security experts and crypto researchers has identified a critical weakness in the AI infrastructure that could be exploited to steal sensitive data and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial, found that 'LLM routers' - services that connect users to AI models - can be used as a powerful attack point by malicious actors. These routers have unrestricted access to user data, including sensitive information, and can modify or steal it.
The researchers warned that users are extremely vulnerable to attack, as they often assume they are interacting directly with a reputable AI model when, in reality, their requests are being routed through intermediary services that can intercept and manipulate their data. One of the researchers, Chaofan Shou, noted that the problem is no longer theoretical, citing an instance where a malicious router drained a client's $500,000 wallet.
The researchers demonstrated how a single compromised router can immediately compromise systems or funds, especially in cases where autonomous systems approve and execute actions without human review. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed.
The team also showed how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers warned that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that could have far-reaching consequences for the crypto industry.