The rapid growth of the cryptocurrency industry is driving the adoption of AI agents to manage various transactions, from travel bookings to trade executions and payments. However, recent research suggests that the underlying infrastructure supporting this shift may be vulnerable to security breaches. According to a report by McKinsey, AI agents are projected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make over a million times more payments than people, all in cryptocurrency. Nevertheless, a team of security academics and crypto researchers has identified a critical flaw in the AI infrastructure that could compromise sensitive data and has already been linked to stolen credentials and a $500,000 wallet drain. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors.
These routers have full access to all data passing through them, including sensitive information, and can be used to steal credentials and drain crypto wallets. The researchers warn that the problem is no longer theoretical, citing cases where LLM routers have been secretly injecting malicious tool calls and stealing credentials, resulting in significant financial losses. The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This highlights a weakest-link problem, where a single malicious router in the chain can compromise the entire system, underscoring the need for greater security guarantees in the underlying infrastructure.