The cryptocurrency sector is rapidly evolving towards an era where AI agents manage various tasks, including transactions and payments, but a new study suggests that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict that AI agents will soon outnumber humans in making transactions on the internet, with a significant portion of these transactions being crypto-based. However, a group of security academics and crypto researchers has identified a critical flaw in the AI infrastructure that can be exploited to steal credentials and drain crypto wallets.
The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and used for malicious purposes.
The researchers demonstrated that a single malicious router can compromise an entire system, highlighting a weakest-link problem in the infrastructure. This vulnerability can have severe implications for crypto users, as it can lead to the exposure of sensitive information and significant financial losses. The study's findings suggest that the increasing reliance on AI agents in the crypto industry may be compromised by the lack of security guarantees in the underlying infrastructure.