The rapid growth of AI agents in the cryptocurrency industry is expected to revolutionize the way transactions are made, with predictions suggesting that AI agents will soon handle a substantial portion of global consumer commerce. However, a team of researchers has discovered a critical flaw in the underlying infrastructure that could put users' sensitive data and wallets at risk. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used to steal credentials and drain crypto wallets.

These routers have full access to sensitive data, including private keys and API credentials, and can modify or exfiltrate this information without the user's knowledge. The study reveals that a single malicious router in the chain can compromise the entire system, highlighting a weakest-link problem that poses a significant risk to crypto users. The researchers demonstrated the vulnerability of these systems by poisoning parts of the router ecosystem and gaining control of hundreds of downstream systems within hours. The implications of this discovery are severe, as it suggests that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, creating a potential mismatch between the predicted growth of AI-powered crypto activity and the lack of guarantees that outputs haven't been tampered with.