The rapid evolution of the cryptocurrency industry is driving towards a future where AI agents manage various tasks, including payments and transactions. However, a newly released research paper suggests that the underlying infrastructure supporting this shift may be insecure.

According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Prominent figures in the industry, such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao, predict that AI agents will soon outnumber humans in making transactions on the internet, with a significant portion of these transactions being crypto-based. Nevertheless, a group of security academics and crypto researchers have identified a critical flaw in the AI infrastructure that is already being exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that 'LLM routers' or services that connect users to AI models can be a powerful attack point for malicious actors.

These routers have complete access to all data passing through them, including sensitive information. The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in the drainage of a client's $500,000 wallet.

They also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The team warned that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.