The rapid advancement of the cryptocurrency industry toward AI-powered transactions, including payments and trades, may be hindered by a significant security flaw in the underlying infrastructure. According to recent projections by McKinsey, AI agents are expected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Prominent figures in the industry, such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict a future where AI agents will outnumber humans in making transactions on the internet, with a significant portion of these transactions being in crypto. However, a group of security academics and crypto researchers has identified a largely overlooked aspect of AI infrastructure that is being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with institutions such as the University of California, Santa Barbara, and the University of California, San Diego, as well as blockchain firm Fuzzland and World Liberty Financial, have published a paper detailing the vulnerability.
They highlight the role of 'LLM routers,' which are services that act as intermediaries between users and AI models, forwarding requests to models like OpenAI or Anthropic. These routers have full access to all data passing through them, including sensitive information, making them powerful attack points for malicious actors. The researchers emphasize that these tools are increasingly being used for real-world financial and operational tasks, beyond their initial use as conversational assistants.
This vulnerability leaves users extremely exposed, as they believe they are interacting directly with a reputable AI model, when in fact their requests are passing through intermediary services that can view and modify their data. One of the researchers, Chaofan Shou, noted that the issue is no longer theoretical, citing an instance where 26 LLM routers were found to be secretly injecting malicious tool calls and stealing credentials, resulting in the draining of a $500,000 wallet. The researchers also demonstrated the ease with which these systems can be compromised, showing how a single altered instruction can immediately compromise systems or funds due to their autonomous nature.
For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text, and the researchers found instances where routers collected these secrets. The team further demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This highlights a weakest-link problem, where a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that undermines the trust in AI providers, even if the user trusts their AI provider, the infrastructure in between may not be trustworthy.