The cryptocurrency sector is rapidly adopting AI agents to manage various tasks, including transactions and payments, but a newly discovered flaw in the underlying infrastructure may put users' wallets at risk. According to a report by McKinsey, AI agents are expected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. However, a group of researchers from the University of California, Santa Barbara, the University of California, San Diego, and other institutions has identified a vulnerability in the AI infrastructure that could be exploited by malicious actors to steal credentials and drain crypto wallets. The researchers found that so-called LLM routers, which act as intermediaries between users and AI models, can be used to intercept sensitive data, including private keys and API credentials.

This vulnerability can be used to compromise entire systems, even if a user trusts their AI provider, as the infrastructure in between may not be secure. The researchers demonstrated the severity of the issue by poisoning parts of the router ecosystem and gaining control of hundreds of downstream systems within hours.

The study highlights the need for increased security measures to protect users' sensitive information and prevent potential losses.