The cryptocurrency sector is moving towards a future where AI-powered agents manage various transactions, but research suggests that the underlying infrastructure may be insecure. According to a recent projection by McKinsey, AI agents could facilitate $3 trillion to $5 trillion of global consumer commerce by 2030. However, a team of security academics and crypto researchers has identified a largely overlooked vulnerability in AI infrastructure that can be exploited by malicious actors to steal credentials and drain crypto wallets.
The vulnerability lies in so-called 'LLM routers,' which are services that sit between users and AI models. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, making users extremely vulnerable to attacks.
The researchers found that a single malicious router can compromise the entire system, and they demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a potential mismatch between the growing use of AI agents in crypto activity and the lack of guarantees that outputs haven't been tampered with.