The crypto industry is advancing towards an AI-driven future where agents manage tasks such as flight bookings, transactions, and payments, but recent research indicates that the underlying infrastructure may be insecure. According to McKinsey, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders like Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict an explosion in AI-driven transactions. However, a group of security researchers has identified a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets.
The researchers found that so-called 'LLM routers' can act as a powerful attack point, allowing malicious actors to intercept and modify sensitive data. These routers, which forward requests to AI models, have full access to all data passing through them, leaving users vulnerable to attack. The problem is no longer theoretical, with one researcher reporting that 26 LLM routers have been found to be secretly injecting malicious code and stealing credentials, resulting in a $500,000 wallet drain.
The researchers warn that a single malicious router can compromise an entire system, and that the use of AI agents in crypto transactions creates a cascading risk of attack. The study highlights the need for greater security guarantees in the underlying infrastructure to prevent such attacks and ensure the secure use of AI-powered crypto payments.