The rapid growth of AI-driven cryptocurrency transactions has sparked concerns over the security of the underlying infrastructure. According to a recent study, AI agents are projected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Industry leaders, including Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict that AI agents will soon dominate online transactions, with the latter forecasting that agents will make one million times more payments than people, all in crypto. However, a group of security academics and crypto researchers has identified a critical vulnerability in the AI infrastructure that could expose users to significant risks.

The researchers found that so-called 'LLM routers,' which act as intermediaries between users and AI models, can be exploited by malicious actors to steal sensitive data, including credentials and private keys. These routers have full access to all data passing through them, making them a powerful attack point. The researchers warned that users are often unaware that their requests are being routed through these intermediary services, which can modify or steal sensitive information. In one instance, a test Ethereum wallet was drained after its private key was exposed.

The researchers also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The study highlights the need for greater security guarantees in the AI infrastructure to prevent such vulnerabilities and protect users' sensitive information.