The cryptocurrency sector is advancing towards an AI-driven future, where intelligent agents will manage various tasks, including payments and trades. However, a newly released research paper suggests that the underlying infrastructure may be vulnerable to security breaches. According to the study, AI agents are expected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030, with industry leaders like Brian Armstrong and Changpeng Zhao predicting a significant rise in AI-mediated transactions. Nevertheless, the researchers warn that a largely overlooked component of AI infrastructure, known as LLM routers, can be exploited by malicious actors to steal sensitive data and drain crypto wallets.
These routers, designed to forward requests to AI models, have full access to user data, making them a powerful attack point. The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one incident resulting in a $500,000 wallet drain. The study highlights the severity of the issue, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text, making them vulnerable to exploitation.
The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The researchers emphasize that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even trusted AI providers may not be able to guarantee the security of their infrastructure.