The cryptocurrency sector is moving towards an AI-driven future where agents will manage transactions, trades, and payments, but recent findings suggest that the underlying infrastructure may be vulnerable to security breaches. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.
Meanwhile, industry leaders such as Brian Armstrong and Changpeng Zhao predict a significant rise in AI-powered transactions. However, a group of researchers from the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial have identified a potential flaw in the AI infrastructure that could be exploited by malicious actors. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used to steal sensitive data, including credentials and private keys. These routers have the ability to access and modify data, leaving users vulnerable to attacks.
The researchers demonstrated that a single malicious router can compromise an entire system, and that the problem is no longer theoretical, with reported cases of stolen credentials and a $500,000 wallet hack. The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers warn that the lack of security guarantees in the AI infrastructure could lead to a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.