• bitcoinBitcoin (BTC) $ 77,265.00
  • ethereumEthereum (ETH) $ 2,134.27
  • tetherTether (USDT) $ 0.999433
  • bnbBNB (BNB) $ 642.32
  • xrpXRP (XRP) $ 1.39
  • usd-coinUSDC (USDC) $ 0.999829
  • solanaSolana (SOL) $ 85.01
  • tronTRON (TRX) $ 0.356399
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.105213
  • whitebitWhiteBIT Coin (WBT) $ 56.71
  • usdsUSDS (USDS) $ 0.999699
  • hyperliquidHyperliquid (HYPE) $ 45.43
  • cardanoCardano (ADA) $ 0.251250
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.08
  • zcashZcash (ZEC) $ 524.33
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 356.85
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 386.11
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.52
  • canton-networkCanton (CC) $ 0.153066
  • the-open-networkToncoin (TON) $ 1.95
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.148189
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999587
  • ethena-usdeEthena USDe (USDE) $ 0.999830
  • suiSui (SUI) $ 1.05
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • litecoinLitecoin (LTC) $ 53.85
  • memecoreMemeCore (M) $ 3.18
  • avalanche-2Avalanche (AVAX) $ 9.16
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.089083
  • rainRain (RAIN) $ 0.007464
  • paypal-usdPayPal USD (PYUSD) $ 0.999938
  • usdt0USDT0 (USDT0) $ 0.998824
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • crypto-com-chainCronos (CRO) $ 0.069408
  • global-dollarGlobal Dollar (USDG) $ 0.999836
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,554.18
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 259.23
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • uniswapUniswap (UNI) $ 3.44
  • pax-goldPAX Gold (PAXG) $ 4,552.10
  • polkadotPolkadot (DOT) $ 1.24
  • mantleMantle (MNT) $ 0.629245
  • nearNEAR Protocol (NEAR) $ 1.52
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.060233
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.998484
  • okbOKB (OKB) $ 82.09
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.651122
  • ondo-financeOndo (ONDO) $ 0.339672
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • skySky (SKY) $ 0.069286
  • pi-networkPi Network (PI) $ 0.150939
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • pepePepe (PEPE) $ 0.000004
  • usddUSDD (USDD) $ 1.00
  • internet-computerInternet Computer (ICP) $ 2.54
  • bitget-tokenBitget Token (BGB) $ 1.99
  • ethereum-classicEthereum Classic (ETC) $ 8.78
  • aaveAave (AAVE) $ 89.30
  • bfusdBFUSD (BFUSD) $ 0.999000
  • quant-networkQuant (QNT) $ 75.95
  • usdtbUSDtb (USDTB) $ 0.999391
  • kucoin-sharesKuCoin (KCS) $ 7.95
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • morphoMorpho (MORPHO) $ 1.67
  • cosmosCosmos Hub (ATOM) $ 2.04
  • united-stablesUnited Stables (U) $ 1.00
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.87
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090296
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • algorandAlgorand (ALGO) $ 0.106577
  • ethenaEthena (ENA) $ 0.104625
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.034376
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.77
  • nexoNEXO (NEXO) $ 0.859086
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • stable-2​​Stable (STABLE) $ 0.037731
  • worldcoin-wldWorldcoin (WLD) $ 0.234312
  • wbnbWrapped BNB (WBNB) $ 759.61
  • flare-networksFlare (FLR) $ 0.008830
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • justJUST (JST) $ 0.088504
  • aptosAptos (APT) $ 0.929979
  • gatechain-tokenGate (GT) $ 7.10
  • filecoinFilecoin (FIL) $ 0.943361
  • arbitrumArbitrum (ARB) $ 0.116133
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • dexeDeXe (DEXE) $ 13.90
  • jupiter-exchange-solanaJupiter (JUP) $ 0.195433
  • venice-tokenVenice Token (VVV) $ 13.90
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • xdce-crowd-saleXDC Network (XDC) $ 0.030880
  • beldexBeldex (BDX) $ 0.078732
  • pump-funPump.fun (PUMP) $ 0.001703
  • ghoGHO (GHO) $ 0.999423
  • vechainVeChain (VET) $ 0.006706
  • hash-2Provenance Blockchain (HASH) $ 0.010599
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.998416
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ousgOUSG (OUSG) $ 115.25
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • yldsYLDS (YLDS) $ 0.999989
  • dashDash (DASH) $ 41.71
  • midnight-3Midnight (NIGHT) $ 0.031884
  • clbtcclBTC (CLBTC) $ 76,920.00
  • kite-2Kite (KITE) $ 0.230598
  • bonkBonk (BONK) $ 0.000006
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008289
  • true-usdTrueUSD (TUSD) $ 0.999138
  • chilizChiliz (CHZ) $ 0.047658
  • apxusdapxUSD (APXUSD) $ 0.999841
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • official-trumpOfficial Trump (TRUMP) $ 2.08
  • a7a5A7A5 (A7A5) $ 0.012474
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.42
  • tbtctBTC (TBTC) $ 70,942.00
  • humanityHumanity (H) $ 0.249891
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.699726
  • injective-protocolInjective (INJ) $ 4.59
  • euro-coinEURC (EURC) $ 1.16
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000079
  • blockstackStacks (STX) $ 0.233395
  • edgexedgeX (EDGE) $ 1.22
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.189086
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.418659
  • adi-tokenADI (ADI) $ 4.00
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • sei-networkSei (SEI) $ 0.060457
  • usdgoUSDGO (USDGO) $ 0.999810
  • unibaseUnibase (UB) $ 0.156155
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997726
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • build-onBUILDon (B) $ 0.387378
  • sun-tokenSun Token (SUN) $ 0.019992
  • aerodrome-financeAerodrome Finance (AERO) $ 0.407077
  • labLAB (LAB) $ 4.93
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • usxUSX (USX) $ 0.999878
  • tezosTezos (XTZ) $ 0.343241
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • siren-2Siren (SIREN) $ 0.501044
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • celestiaCelestia (TIA) $ 0.386004
  • billions-networkBillions Network (BILL) $ 0.145656
  • curve-dao-tokenCurve DAO (CRV) $ 0.233531
  • kinesis-goldKinesis Gold (KAU) $ 146.07
  • spx6900SPX6900 (SPX) $ 0.363345
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • ether-fiEther.fi (ETHFI) $ 0.378151
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • layerzeroLayerZero (ZRO) $ 1.28
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • monadMonad (MON) $ 0.027047
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • skyaiSkyAI (SKYAI) $ 0.317023
  • gnosisGnosis (GNO) $ 118.54
  • hastra-primePRIME (PRIME) $ 1.04
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • doublezeroDoubleZero (2Z) $ 0.089201
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • pendlePendle (PENDLE) $ 1.80
  • kaiaKaia (KAIA) $ 0.051922
  • conflux-tokenConflux (CFX) $ 0.058379
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • bitcoin-svBitcoin SV (BSV) $ 15.03
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

AI agents are set to power crypto payments, but a hidden flaw could expose wallets

0 22

AI agents are set to power crypto payments, but a hidden flaw could expose wallets

The cryptocurrency industry is racing toward a future where AI agents handle everything from booking flights to executing trades and making payments, but new research suggests the infrastructure underpinning that shift may not be secure.

McKinsey recently projected that AI agents could mediate $3 trillion to $5 trillion of global consumer commerce by 2030.

Coinbase founder Brian Armstrong said on X that “very soon” there will be more AI agents than humans making transactions on the internet. Binance founder Changpeng Zhao was more bold, predicting agents will make one million times more payments than people, all in crypto.

But a group of security academic and crypto researchers have released a paper explaining that a largely overlooked piece of AI infrastructure is already being used to steal credentials and even drain crypto wallets.

The authors of the papers are researchers affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland and World Liberty Financial.

Powerful attack points

The team found that so-called “LLM routers,” or services that sit between users and AI models, can act as a powerful attack point exploited by malicious actors. These routers are designed to forward requests to models like OpenAI or Anthropic, but they also have full access to everything passing through them, including sensitive data.

“LLM agents have moved beyond conversational assistants into systems that book flights, execute code, and manage infrastructure on behalf of users,” the researchers wrote, highlighting how quickly these tools are taking on real-world financial and operational tasks.

The LLM routers or attack points leave users extremely vulnerable as they assume they are interacting directly with a reputable AI model such as OpenAI, Grok or otherwise, when in reality many requests pass through intermediary services that can see and modify that data, the researchers said.

According to one of the researchers, Chaofan Shou, the problem is no longer theoretical. He wrote on X that “26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet. We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.”

“A malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it,” the researchers wrote.

The researchers said that because these systems can operate autonomously, including frequently approving and executing actions without human review, a single altered instruction can immediately compromise systems or funds.

For crypto users, the implications are severe as private keys, API credentials and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers simply collected those secrets, the paper reveals. In one instance, a test Ethereum wallet was drained after its private key was exposed.

“Once exposed, credentials like private keys can be copied and reused without the user’s knowledge,” the authors of the paper noted.

Cascading risks

The team also demonstrated how easy it is to expand the attack. By “poisoning” parts of the router ecosystem, essentially tricking services into forwarding traffic, they were able to observe and potentially control hundreds of downstream systems within hours.

“A single malicious router in the chain is enough to compromise the entire system,” the researchers wrote, underscoring what they describe as a weakest-link problem.

That suggests a cascading risk of even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, they stated in their paper.

That creates a potential mismatch as industry leaders increasingly predict AI agents will handle a growing share of crypto activity, while the underlying infrastructure still lacks guarantees that outputs haven’t been tampered with, they added.

Source

Leave A Reply

Your email address will not be published.