The crypto industry is on the cusp of a revolution where AI agents manage various transactions, but a new study reveals that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a group of security experts and crypto researchers have identified a significant vulnerability in the AI infrastructure, which has already been exploited to steal credentials and drain crypto wallets. The researchers found that 'LLM routers' or services that connect users to AI models can be used as a powerful attack point by malicious actors.
These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and modified. The implications for crypto users are severe, as a single compromised router can immediately compromise systems or funds. The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a significant weakest-link problem in the AI-powered crypto payment ecosystem.