The crypto industry is moving towards an AI-driven future, where agents manage transactions, trades, and payments, but recent research reveals that the underlying infrastructure may be insecure. According to McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a team of security academics and crypto researchers has discovered a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets.
The researchers found that 'LLM routers' or services that connect users to AI models can act as a powerful attack point, allowing malicious actors to access sensitive data. These routers have full access to all data passing through them, including sensitive information, and can modify or steal it. The researchers demonstrated that a single malicious router can compromise an entire system, and by 'poisoning' parts of the router ecosystem, they were able to control hundreds of downstream systems within hours.
This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text, making them vulnerable to theft and exploitation.