The cryptocurrency sector is rapidly advancing towards an era where AI agents manage a wide range of tasks, from travel bookings to trade executions and payments. However, recent findings suggest that the underlying infrastructure supporting this shift may be flawed. A report by McKinsey estimates that AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Prominent figures in the industry, such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict that AI agents will soon surpass humans in making transactions on the internet, with a significant portion being crypto-based.
Nevertheless, a group of security academics and crypto researchers have published a paper highlighting a largely overlooked vulnerability in AI infrastructure that has already been exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have identified a critical weakness in 'LLM routers,' which are services that act as intermediaries between users and AI models. These routers, designed to forward requests to models like OpenAI or Anthropic, have unrestricted access to all data passing through them, including sensitive information.
The researchers emphasize that LLM agents have evolved beyond conversational assistants, taking on real-world financial and operational tasks, and that the vulnerability in LLM routers leaves users extremely susceptible to attacks. According to the researchers, malicious actors can exploit this weakness to inject malicious tool calls, steal credentials, and even drain wallets.
In one instance, a test Ethereum wallet was drained after its private key was exposed. The researchers warn that because these systems can operate autonomously, a single altered instruction can immediately compromise systems or funds. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.
The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. Furthermore, the team demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers stress that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.