The cryptocurrency sector is on the cusp of an AI-driven revolution, with agents poised to manage transactions, trades, and payments, but recent findings suggest the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts an imminent future where AI agents will outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts a million-fold increase in AI-driven crypto payments. However, a team of security academics and crypto researchers has identified a critical vulnerability in the AI infrastructure, which has already been exploited to steal credentials and drain crypto wallets.
The researchers, affiliated with the University of California and blockchain firm Fuzzland, discovered that LLM routers, which act as intermediaries between users and AI models, can be manipulated by malicious actors to access sensitive data. These routers, designed to forward requests to models like OpenAI, have full access to user data, including sensitive information. The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain.
The team demonstrated how a single compromised router can compromise an entire system, highlighting a weakest-link problem in the AI infrastructure. This vulnerability has severe implications for crypto users, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.
The researchers warn that the lack of guarantees regarding the integrity of AI outputs poses a cascading risk, even if users trust their AI providers.