The rapid growth of AI agents in the crypto industry, predicted to handle $3 trillion to $5 trillion in consumer commerce by 2030, may be compromised by a previously overlooked security flaw. Researchers from the University of California and other institutions have identified a weakness in LLM routers, which act as intermediaries between users and AI models, allowing malicious actors to intercept sensitive data.
This vulnerability has already been exploited to steal credentials and drain crypto wallets, including a $500,000 hack. The researchers found that these routers can modify or exfiltrate data, including private keys and wallet access tokens, without users' knowledge. The implications are severe, with a single compromised router able to compromise an entire system, highlighting a weakest-link problem in the AI infrastructure.
As industry leaders predict a surge in AI-powered crypto activity, the lack of security guarantees in the underlying infrastructure poses a significant risk to users.