The cryptocurrency sector is on the cusp of a revolution where AI agents will manage various transactions, but recent findings suggest that the underlying infrastructure may be insecure. According to a recent McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict that AI agents will soon surpass humans in making transactions on the internet, with the latter forecasting that agents will make one million times more payments than people in crypto. However, a team of security academics and crypto researchers has discovered that a crucial component of AI infrastructure, known as LLM routers, can be exploited by malicious actors to steal credentials and drain crypto wallets.
The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that these routers can act as a powerful attack point, allowing malicious actors to access sensitive data. The team noted that LLM agents have evolved beyond conversational assistants and now perform real-world financial and operational tasks, such as booking flights and managing infrastructure. However, the use of intermediary services, or LLM routers, leaves users vulnerable to attack, as these services can see and modify sensitive data. According to researcher Chaofan Shou, the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.
The researchers warned that a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it, allowing for the immediate compromise of systems or funds. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.
The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
The researchers concluded that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.