The cryptocurrency sector is rapidly advancing towards an AI-driven future where agents will manage various tasks, including transactions and payments. However, recent findings suggest that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make one million times more payments than people, all in crypto. A group of security academics and crypto researchers have published a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure. The researchers, affiliated with the University of California, discovered that 'LLM routers,' which act as intermediaries between users and AI models, can be exploited by malicious actors. These routers have full access to sensitive data, including credentials and wallet information.
The team found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, with one incident resulting in a $500,000 wallet drain. The problem is exacerbated by the fact that users often assume they are interacting directly with reputable AI models, when in reality, their requests are passing through intermediary services that can modify or steal their data.
The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.
As industry leaders predict AI agents will handle a growing share of crypto activity, the underlying infrastructure lacks guarantees that outputs haven't been tampered with.