The rapid adoption of AI agents in the cryptocurrency industry, projected to facilitate $3 trillion to $5 trillion in global consumer commerce by 2030, may be hindered by a previously overlooked security vulnerability. According to researchers from the University of California, blockchain firm Fuzzland, and World Liberty Financial, a key component of AI infrastructure, known as LLM routers, can be exploited by malicious actors to steal credentials and drain crypto wallets. These routers, designed to forward requests to AI models, have unrestricted access to sensitive data, leaving users vulnerable to attack.

The researchers found that 26 LLM routers were secretly injecting malicious tool calls, resulting in the theft of $500,000 from a client's wallet. The study highlights the severe implications for crypto users, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text, making them susceptible to interception and exploitation. The team also demonstrated how a single malicious router can compromise the entire system, creating a cascading risk that undermines the security of the AI-powered crypto payment ecosystem.