The crypto industry is rapidly embracing AI agents to facilitate various transactions, but a recent study reveals that the underlying infrastructure may be insecure. According to McKinsey, AI agents could potentially mediate between $3 trillion to $5 trillion in global consumer commerce by 2030.
However, a group of security researchers has identified a critical vulnerability in a largely overlooked aspect of AI infrastructure, which can be exploited to steal credentials and drain crypto wallets. The researchers found that 'LLM routers,' which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have unrestricted access to sensitive data, including private keys and API credentials, making users extremely vulnerable. The researchers demonstrated that a single malicious router can compromise an entire system, and they were able to 'poison' parts of the router ecosystem, gaining control over hundreds of downstream systems within hours.
This discovery highlights a significant weakest-link problem, where the trustworthiness of the infrastructure is compromised, even if the user trusts their AI provider. As industry leaders predict that AI agents will handle an increasing share of crypto activity, the lack of guarantees that outputs haven't been tampered with poses a significant risk.