The cryptocurrency industry is rapidly adopting AI agents to manage transactions, trades, and payments, but research suggests that the underlying infrastructure may be vulnerable to security breaches. According to a recent projection by McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a group of security researchers has identified a critical flaw in the AI infrastructure that could compromise user data and expose wallets to theft. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used to steal credentials and drain crypto wallets.

These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, making them a powerful attack point for malicious actors. The researchers demonstrated that a single malicious router can compromise an entire system, and they were able to observe and control hundreds of downstream systems within hours by poisoning parts of the router ecosystem.

The implications for crypto users are severe, as exposed credentials can be copied and reused without the user's knowledge, and the researchers found multiple cases where routers collected sensitive data. The study highlights the need for greater security measures to protect user data and prevent potential breaches in the AI infrastructure used in crypto payments.