The crypto industry is on the verge of a revolution where AI agents will manage various transactions, from flight bookings to trades and payments. However, a new study suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion of global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make one million times more crypto payments than people.
A group of security academics and crypto researchers have identified a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that so-called 'LLM routers' can act as a powerful attack point for malicious actors.
These routers, designed to forward requests to AI models like OpenAI or Anthropic, have full access to sensitive data passing through them. The researchers noted that LLM agents have moved beyond conversational assistants to manage real-world financial and operational tasks, making users vulnerable to attacks.
The LLM routers can see and modify data, leaving users unaware that they are interacting with intermediary services rather than reputable AI models. According to researcher Chaofan Shou, the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.
The researchers warned that a malicious router can replace benign commands with attacker-controlled ones or silently exfiltrate credentials, compromising systems or funds. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.
The researchers found multiple cases where routers collected these secrets, including an instance where a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The researchers emphasized that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.