The rapid advancement of AI agents in the cryptocurrency industry, projected to mediate $3 trillion to $5 trillion in global consumer commerce by 2030, has introduced a significant security concern. Researchers from the University of California and other institutions have identified a vulnerability in the AI infrastructure, specifically in LLM routers, which can be exploited by malicious actors to steal credentials and drain crypto wallets.

These routers, designed to forward requests to AI models, have full access to sensitive data and can modify it, leaving users vulnerable to attack. The researchers have demonstrated the severity of the issue, with one instance resulting in a $500,000 wallet drain.

The vulnerability poses a significant risk to crypto users, as private keys, API credentials, and wallet access tokens are often transmitted in plain text through these systems. The researchers have also shown that a single malicious router can compromise the entire system, highlighting a weakest-link problem in the AI infrastructure. This raises concerns about the security of AI-powered crypto payments, as industry leaders predict a growing reliance on AI agents for transactions.