The cryptocurrency sector is moving towards an AI-driven future where agents manage various tasks, including transactions and payments. However, research suggests that the underlying infrastructure may be insecure. According to a projection by McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make millions of times more payments than people, all in crypto.
A group of security researchers and academics has released a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure, which can be exploited by malicious actors to steal credentials and drain crypto wallets. The researchers found that LLM routers, which sit between users and AI models, can act as a powerful attack point, giving malicious actors full access to sensitive data. These routers are designed to forward requests to models like OpenAI or Anthropic but can also modify data, leaving users vulnerable. The researchers warned that a single malicious router can compromise an entire system, and the problem is no longer theoretical, with reported cases of stolen credentials and drained wallets.
The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, potentially controlling hundreds of downstream systems within hours.
The study highlights the need for increased security measures to protect users from these vulnerabilities.