The cryptocurrency sector is rapidly moving towards an AI-driven future where intelligent agents manage various tasks, including transactions and payments. However, a new research paper suggests that the underlying infrastructure supporting this shift may be vulnerable to security breaches.
According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make a million times more payments than people, all in crypto. Nevertheless, a team of security academics and crypto researchers has identified a significant flaw in the AI infrastructure that could be exploited to steal credentials and drain crypto wallets.
The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including user credentials and financial information, making them a significant vulnerability in the AI infrastructure.
The researchers warn that users are extremely vulnerable to these attacks, as they often assume they are interacting directly with a reputable AI model when, in reality, their requests are passing through intermediary services that can see and modify their data. One of the researchers, Chaofan Shou, revealed that the problem is no longer theoretical, citing an instance where 26 LLM routers were found to be secretly injecting malicious tool calls and stealing credentials, resulting in the drainage of a $500,000 wallet. The researchers demonstrated how a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it, highlighting the severe implications for crypto users. As private keys, API credentials, and wallet access tokens often pass through these systems in plain text, the researchers found multiple cases where routers simply collected those secrets.
The team also showed how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers emphasize that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.