The rapid growth of AI in the cryptocurrency industry, projected to facilitate $3 trillion to $5 trillion in global consumer commerce by 2030, is hindered by a previously overlooked security vulnerability. According to a recent study, a key component of AI infrastructure, known as LLM routers, can be used to steal sensitive information and drain crypto wallets. These routers, which act as intermediaries between users and AI models, have the ability to access and modify sensitive data, leaving users vulnerable to attack.
The researchers found that malicious actors can exploit these routers to intercept credentials, including private keys and API credentials, and use them to gain unauthorized access to crypto wallets. In one instance, a test Ethereum wallet was drained after its private key was exposed.
The study highlights the need for increased security measures to protect users and prevent potential financial losses. The implications of this vulnerability are severe, and the researchers warn that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, creating a potential mismatch between the growing use of AI in crypto and the lack of guarantees that outputs haven’t been tampered with.