The rapid growth of AI agents in the crypto industry, predicted to handle $3 trillion to $5 trillion in consumer commerce by 2030, may be hindered by a significant security flaw. Researchers have identified a weakness in the AI infrastructure, specifically in LLM routers, which can intercept sensitive data and have already been linked to stolen credentials and a $500,000 wallet drain. These routers, designed to forward requests to AI models, have full access to user data, including private keys, API credentials, and wallet access tokens. The researchers found that malicious routers can replace benign commands with attacker-controlled ones, exfiltrate credentials, and compromise systems or funds without human review.
The implications for crypto users are severe, with private keys, API credentials, and wallet access tokens often passing through these systems in plain text. The team demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, potentially controlling hundreds of downstream systems within hours. This highlights a weakest-link problem, where a single malicious router in the chain can compromise the entire system, creating a cascading risk for users who trust their AI provider but not the infrastructure in between.