The crypto industry is moving towards an AI-driven future, where agents will manage transactions, trades, and payments, but research reveals a potential security flaw in the underlying infrastructure. According to a recent McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.

Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, with Binance founder Changpeng Zhao forecasting a significant increase in AI-driven crypto payments. However, a team of security researchers and academics has identified a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be stolen or modified.

The researchers demonstrated that a single malicious router can compromise an entire system, and by 'poisoning' parts of the router ecosystem, they were able to observe and control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a potential mismatch between the growing use of AI agents in crypto and the lack of guarantees that the underlying infrastructure is secure.