The cryptocurrency sector is rapidly advancing towards an era where AI-driven agents manage various tasks, including transactions and payments. However, a new research study suggests that the underlying infrastructure may be vulnerable to security breaches.
According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, with Binance founder Changpeng Zhao forecasting that agents will make a staggering one million times more payments than people, all in cryptocurrency. Nevertheless, a group of security academics and crypto researchers have published a paper highlighting a significant flaw in the AI infrastructure that can be exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, discovered that 'LLM routers,' which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors.
These routers have unrestricted access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and used for malicious purposes. The study found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers warn that a single compromised router can compromise the entire system, posing a significant risk to crypto users. The team demonstrated how easily the attack can be expanded by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours.
The study highlights a weakest-link problem, where a single malicious router can compromise the entire system, even if the user trusts their AI provider. This creates a potential mismatch between the growing reliance on AI agents for crypto transactions and the lack of guarantees that the underlying infrastructure is secure.