todayonchain.com

Researchers discover malicious AI agent routers that can steal crypto

Cointelegraph
University of California researchers found that third-party AI routers can inject malicious code and steal sensitive crypto credentials from LLM users.

Summary

Researchers from the University of California have identified security vulnerabilities in third-party AI LLM routers that facilitate crypto theft. By testing 428 routers, they discovered that some actively inject malicious code, harvest credentials, or drain Ethereum wallets. These routers operate as intermediaries with plaintext access to sensitive data, posing significant risks to developers using AI agents for blockchain tasks. The study highlights the danger of 'YOLO mode,' where agents execute commands without human confirmation, and recommends enhanced client-side defenses and cryptographic verification to secure the AI supply chain.

(Source:Cointelegraph)