The rapid advancement of AI agents in the cryptocurrency industry, projected to handle $3 trillion to $5 trillion in global consumer commerce by 2030, may be hindered by a significant security flaw. Researchers from the University of California, Santa Barbara, the University of California, San Diego, and other institutions have discovered that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors to steal credentials and drain crypto wallets. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which are often transmitted in plain text. The researchers found that a single malicious router can compromise an entire system, allowing attackers to replace benign commands with malicious ones or exfiltrate credentials without detection.
This vulnerability has already been linked to stolen credentials and a $500,000 wallet drain, highlighting the need for increased security measures to protect user wallets and prevent potential cascading risks.