The rapid growth of AI agents in the cryptocurrency industry, projected to handle trillions of dollars in consumer commerce by 2030, has raised concerns about the security of the underlying infrastructure. According to recent research, a largely overlooked component of AI infrastructure, known as LLM routers, can be exploited by malicious actors to steal credentials and drain crypto wallets. These routers, designed to forward requests to AI models, have full access to sensitive data, including private keys, API credentials, and wallet access tokens.

The researchers found that multiple LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain. The vulnerability is exacerbated by the autonomous nature of these systems, which can approve and execute actions without human review, allowing a single altered instruction to immediately compromise systems or funds. The implications for crypto users are severe, with private keys, API credentials, and wallet access tokens often passing through these systems in plain text.

The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a weakest-link problem in the AI-powered crypto payment ecosystem.