The cryptocurrency industry is rapidly embracing a future where AI agents manage various tasks, including transactions and payments. However, a recent research paper suggests that the underlying infrastructure may be insecure. According to McKinsey, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make one million times more crypto payments than people.
Nevertheless, a team of security academics and crypto researchers has discovered that a frequently overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be a powerful attack point for malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, making users extremely vulnerable. The problem is no longer theoretical, as one researcher reported that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.
The researchers warn that a single malicious router can compromise systems or funds, and the implications for crypto users are severe. The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, as even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.