The cryptocurrency sector is rapidly advancing towards an era where AI agents will manage various tasks, including travel bookings, trade executions, and transactions. However, new research indicates that the underlying infrastructure supporting this shift may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon surpass humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make significantly more crypto payments than people.
A group of security academics and crypto researchers have published a paper highlighting the risks associated with a widely overlooked AI infrastructure component, which has already been linked to credential theft and crypto wallet drains. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, identified 'LLM routers' as a key vulnerability. These services, designed to forward requests to AI models like OpenAI or Anthropic, have full access to sensitive data passing through them.
The researchers found that malicious actors can exploit these routers to steal credentials and drain crypto wallets, with one instance resulting in a $500,000 wallet drain. The team demonstrated how easily the attack can be expanded by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
This creates a weakest-link problem, where a single malicious router can compromise the entire system, even if a user trusts their AI provider. The study highlights a potential mismatch between the growing reliance on AI agents for crypto activity and the lack of guarantees that the underlying infrastructure is secure.