The cryptocurrency sector is rapidly moving towards a future where AI agents manage various tasks, including payments and transactions. However, a recent research paper suggests that the underlying infrastructure may be insecure.

According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao estimating that agents will make one million times more payments than people, all in crypto. A group of security academics and crypto researchers have identified a critical vulnerability in the AI infrastructure, which can be exploited to steal credentials and drain crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors.

These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens. The researchers demonstrated that a single malicious router can compromise an entire system, and they were able to observe and control hundreds of downstream systems within hours by poisoning parts of the router ecosystem. The study highlights a significant mismatch between the growing use of AI agents in crypto transactions and the lack of guarantees that the underlying infrastructure is secure.