The rapid growth of the cryptocurrency industry is driving the adoption of AI agents to manage various tasks, including payments and transactions. However, a new research paper highlights a critical security flaw in the underlying infrastructure that supports these AI-powered systems. According to the study, a type of AI infrastructure known as LLM routers can be exploited by malicious actors to steal sensitive data, including credentials and private keys.
These routers act as intermediaries between users and AI models, allowing them to access and modify sensitive information. The researchers found that several LLM routers are already being used to steal credentials and drain crypto wallets, with one instance resulting in a $500,000 loss. The study's authors warn that the problem is no longer theoretical and that a single compromised router can put the entire system at risk.
The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
The study highlights a weakest-link problem, where a single malicious router in the chain can compromise the entire system, even if a user trusts their AI provider. This creates a potential mismatch between the growing use of AI agents in crypto transactions and the lack of guarantees that the underlying infrastructure is secure.