The cryptocurrency sector is rapidly advancing towards a future where AI agents manage various tasks, including payments and transactions, but a newly released research paper suggests that the underlying infrastructure may be flawed. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong has stated that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao predicting that agents will make significantly more payments than people, all in crypto.

However, a group of security academics and crypto researchers have identified a critical vulnerability in a largely overlooked component of AI infrastructure, which has already been exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that LLM routers, which act as intermediaries between users and AI models, can be used as powerful attack points by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and modified.

The researchers demonstrated that a single malicious router can compromise an entire system, and they were able to observe and control hundreds of downstream systems within hours by 'poisoning' parts of the router ecosystem. The study highlights the severe implications for crypto users, as exposed credentials can be copied and reused without the user's knowledge, and the lack of guarantees that outputs haven't been tampered with creates a potential mismatch between the growing use of AI agents in crypto activity and the underlying infrastructure's security.