The cryptocurrency sector is rapidly advancing towards an era where AI agents manage various transactions, including payments and trades. However, a recent research paper suggests that the underlying infrastructure supporting this shift may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make a million times more payments than people, all in crypto.
A group of security academics and crypto researchers have identified a largely overlooked aspect of AI infrastructure that is being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that LLM routers, which act as intermediaries between users and AI models, can be a powerful attack point for malicious actors. These routers have full access to sensitive data passing through them, leaving users vulnerable to attacks. The researchers noted that LLM agents have evolved beyond conversational assistants to manage real-world financial and operational tasks, making them a prime target for malicious actors.
The problem is no longer theoretical, as one of the researchers, Chaofan Shou, reported that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers demonstrated how a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it.
For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers collected those secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
A single malicious router in the chain is enough to compromise the entire system, underscoring a weakest-link problem. This creates a potential mismatch between the growing use of AI agents in crypto activity and the lack of guarantees that the underlying infrastructure is secure.