The cryptocurrency sector is on the cusp of a future where AI agents manage various tasks, including transactions and payments. However, recent research suggests that the underlying infrastructure may be insecure.

According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao estimating that agents will make one million times more payments than people, all in crypto. A group of security academics and crypto researchers have released a paper highlighting a largely overlooked piece of AI infrastructure that is being used to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that LLM routers, which sit between users and AI models, can act as a powerful attack point exploited by malicious actors.

These routers have full access to everything passing through them, including sensitive data. The researchers noted that LLM agents have moved beyond conversational assistants into systems that book flights, execute code, and manage infrastructure on behalf of users, making them vulnerable to attack.

The LLM routers leave users extremely vulnerable as they assume they are interacting directly with a reputable AI model, when in reality many requests pass through intermediary services that can see and modify that data. According to researcher Chaofan Shou, the problem is no longer theoretical, with 26 LLM routers secretly injecting malicious tool calls and stealing credentials, including one instance where a client's $500k wallet was drained.

The researchers warned that a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers simply collected those secrets. In one instance, a test Ethereum wallet was drained after its private key was exposed.

The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, essentially tricking services into forwarding traffic, and were able to observe and potentially control hundreds of downstream systems within hours. A single malicious router in the chain is enough to compromise the entire system, underscoring a weakest-link problem. This suggests a cascading risk, even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.