The rapid growth of the cryptocurrency industry is driving towards an AI-powered future, where agents will manage various tasks, including transactions and payments. However, recent studies suggest that the underlying infrastructure may be vulnerable to security breaches. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Industry leaders such as Brian Armstrong and Changpeng Zhao predict that AI agents will soon surpass human transactions on the internet, with the latter expecting agents to make one million times more payments than people, all in crypto.
A group of security academics and crypto researchers have published a paper highlighting the risks associated with a largely overlooked piece of AI infrastructure, which has already been linked to stolen credentials and crypto wallet drains. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have identified 'LLM routers' as a significant attack point. These services, designed to forward requests to AI models like OpenAI or Anthropic, have full access to sensitive data, including user credentials and financial information.
The researchers found that these routers can act as a powerful attack point, exploited by malicious actors, and can modify or exfiltrate sensitive data. One of the researchers, Chaofan Shou, noted that the problem is no longer theoretical, with 26 LLM routers secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers demonstrated how a single altered instruction can immediately compromise systems or funds, and how these systems can operate autonomously, approving and executing actions without human review.
For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.
The researchers emphasized that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.