The cryptocurrency sector is rapidly adopting AI agents to manage transactions, trades, and payments, but research suggests that the underlying infrastructure may be insecure. According to a recent projection by McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao forecasting that agents will make one million times more payments than people, all in crypto. However, a group of security academics and crypto researchers has released a paper highlighting that a largely overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets.

The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that 'LLM routers' or services that sit between users and AI models can act as a powerful attack point for malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which are often transmitted in plain text.

The researchers demonstrated that a single malicious router can compromise the entire system, emphasizing a weakest-link problem. They also showed that it is relatively easy to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The study's findings have severe implications for crypto users, as exposed credentials can be copied and reused without the user's knowledge.

The researchers warn that the lack of security guarantees in the underlying infrastructure may create a mismatch as industry leaders increasingly predict AI agents will handle a growing share of crypto activity.