Security Flaw in AI Agent Payments Exposes Crypto Wallets to Theft via LLM Routers
AI agents are increasingly being used for automated trading and crypto payments. LLM routers relay requests between applications and models from providers including OpenAI and Anthropic, but their access to plaintext JSON, private keys and API credentials makes them a supply-chain vulnerability. Joint research by the University of California, Santa Barbara, the University of California, San Diego, Fuzzland and World Liberty Financial highlights the risks to assets once agents gain signing authority.
The researchers published a paper on April 9, 2026, after testing 28 paid routers and 400 free ones. They found 26 implicated in injecting malicious tool calls or stealing credentials, while another router transferred ETH from a private key used in the research. CoinDesk reported on April 13 that, according to the researchers, the flaw cost one customer $500,000 from a crypto wallet and allowed the team to take control of about 400 downstream hosts within hours.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.