The rapid growth of the cryptocurrency industry is driving the adoption of AI agents for various tasks, including payments and transactions. However, a new study reveals a significant flaw in the underlying AI infrastructure, which could compromise user wallets and sensitive data. According to the research, a type of AI infrastructure known as LLM routers can be exploited by malicious actors to steal credentials and drain crypto wallets.
These routers act as intermediaries between users and AI models, but they also have access to sensitive information, making them a powerful attack point. The researchers found that 26 LLM routers were secretly injecting malicious code and stealing credentials, resulting in a $500,000 wallet drain. The implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers warn that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that could affect hundreds of downstream systems.
As the use of AI agents in crypto payments continues to grow, the lack of guarantees that outputs haven't been tampered with poses a significant threat to user security.