The cryptocurrency sector is rapidly moving towards a future where AI-driven agents manage various tasks, including transactions and payments. However, a new research study suggests that the underlying infrastructure supporting this shift may be insecure. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make millions of times more payments than people, all in crypto.
A group of security academics and crypto researchers have released a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure, which has already been linked to credential theft and crypto wallet drainage. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, identified 'LLM routers' as a key vulnerability. These services, designed to forward requests to AI models like OpenAI or Anthropic, have full access to sensitive data passing through them, making them a powerful attack point for malicious actors.
The researchers noted that LLM agents have evolved beyond conversational assistants to manage real-world tasks, including booking flights, executing code, and infrastructure management, on behalf of users. This increased autonomy and access to sensitive information leave users extremely vulnerable, as they often assume they are interacting directly with reputable AI models.
According to researcher Chaofan Shou, the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers warned that a malicious router can replace benign commands with attacker-controlled ones or exfiltrate credentials, compromising systems or funds.
For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple instances where routers collected these secrets, including a test Ethereum wallet that was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The study highlights a weakest-link problem, where a single malicious router in the chain can compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.