The cryptocurrency sector is on the cusp of a revolution where AI agents will manage various tasks, including payments and trades. However, a newly released research paper suggests that the underlying infrastructure may be vulnerable to security breaches. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.

Crypto industry leaders, such as Brian Armstrong and Changpeng Zhao, predict that AI agents will soon dominate internet transactions, with the latter forecasting one million times more AI-driven payments than human-initiated ones. A group of researchers from the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial has identified a critical weakness in the AI infrastructure. They found that so-called LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors to steal sensitive data, including credentials and private keys. These routers have unrestricted access to user data, making them a prime target for attackers.

The researchers warned that users are extremely vulnerable to these attacks, as they often assume they are interacting directly with reputable AI models. In reality, many requests pass through intermediary services that can modify or steal sensitive information. One of the researchers, Chaofan Shou, reported that 26 LLM routers have been found to be secretly injecting malicious code and stealing credentials, resulting in a $500,000 wallet drain.

The researchers demonstrated how a single malicious router can compromise an entire system, highlighting the cascading risks associated with this vulnerability. They also showed how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The study's findings have severe implications for crypto users, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.

The researchers found multiple instances where routers collected these secrets, and in one case, a test Ethereum wallet was drained after its private key was exposed. The authors of the paper emphasized that once credentials are exposed, they can be copied and reused without the user's knowledge.

The team's discovery underscores the need for greater security guarantees in the underlying infrastructure, particularly as industry leaders predict an increased reliance on AI agents for crypto transactions.