The cryptocurrency industry is rapidly advancing towards an AI-driven future, where artificial intelligence agents will manage various tasks, including payments and transactions. However, a recent research paper suggests that the underlying infrastructure supporting this shift may be insecure.
According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, while Binance founder Changpeng Zhao forecasts that agents will make one million times more payments than people, all in crypto.
Nevertheless, a group of security academics and crypto researchers have discovered that a largely overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that so-called 'LLM routers' or services that connect users to AI models can be a powerful attack point for malicious actors. These routers are designed to forward requests to models like OpenAI or Anthropic but have full access to all data passing through them, including sensitive information.
The researchers noted that LLM agents have evolved beyond conversational assistants and now manage real-world financial and operational tasks, such as booking flights and executing code. The LLM routers or attack points leave users extremely vulnerable, as they assume they are interacting directly with a reputable AI model when, in reality, many requests pass through intermediary services that can see and modify the data.
According to researcher Chaofan Shou, the problem is no longer theoretical, and 26 LLM routers have been found to be secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain. The researchers warned that a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it. Since these systems can operate autonomously, a single altered instruction can immediately compromise systems or funds.
For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers simply collected those secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, essentially tricking services into forwarding traffic, and were able to observe and potentially control hundreds of downstream systems within hours. The researchers emphasized that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.