The cryptocurrency sector is moving towards an AI-driven future where agents will manage various tasks, including payments and transactions. However, recent research suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make one million times more crypto payments than people. A group of security academics and crypto researchers have published a paper highlighting the risks associated with a largely overlooked piece of AI infrastructure, which has already been linked to credential theft and crypto wallet drains.
The researchers, affiliated with the University of California and other institutions, found that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, making users vulnerable to attacks.
The researchers demonstrated how a single malicious router can compromise an entire system, underscoring the need for increased security measures in the AI infrastructure. The implications are severe, particularly for crypto users, as exposed credentials can be reused without the user's knowledge. The team also showed how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours.
This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.