The cryptocurrency sector is on the verge of a significant shift, with AI agents poised to manage various transactions, from travel bookings to trades and payments. However, a recent research paper highlights a potential security risk in the underlying infrastructure that could compromise the entire system. According to a McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.

Industry leaders, including Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict that AI agents will soon surpass human transaction volumes on the internet, with a significant portion conducted in crypto. A group of security academics and crypto researchers from the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial have identified a critical vulnerability in the AI infrastructure.

Specifically, they found that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors to steal sensitive data, including credentials and private keys. These routers, designed to forward requests to models like OpenAI or Anthropic, have unrestricted access to all data passing through them.

The researchers warn that users are extremely vulnerable, as they often assume they are interacting directly with a reputable AI model, when in fact, their requests may be passing through intermediary services that can modify or steal their data. One of the researchers, Chaofan Shou, confirmed that the issue is no longer theoretical, citing cases where malicious LLM routers have stolen credentials and drained wallets, including a $500,000 wallet hack. The researchers demonstrated how a single malicious router can compromise an entire system, highlighting a weakest-link problem.

They also showed how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.

The researchers found multiple instances where routers collected these secrets, including a test Ethereum wallet that was drained after its private key was exposed. The team emphasized that once credentials like private keys are exposed, they can be copied and reused without the user's knowledge.

The study's findings suggest a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, creating a potential mismatch between the growing use of AI agents in crypto transactions and the lack of guarantees that outputs haven't been tampered with.