The crypto industry is on the cusp of a revolution where AI agents manage various tasks, including payments and trades, but research suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a team of security academics and crypto researchers has identified a significant vulnerability in the AI infrastructure that could allow malicious actors to steal credentials and drain crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be exploited to intercept sensitive data, including private keys and API credentials.
This vulnerability can be used to compromise systems and funds, with severe implications for crypto users. The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The study highlights a cascading risk where a single malicious router can compromise the entire system, underscoring the need for greater security guarantees in the AI infrastructure underlying crypto payments.