The crypto industry is moving towards an AI-driven future where agents manage transactions, trades, and payments, but research suggests the underlying infrastructure may be insecure. A report by McKinsey predicts that AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a group of security researchers has discovered a vulnerability in the AI infrastructure that can be exploited to steal credentials and drain crypto wallets.

The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be stolen and reused without the user's knowledge.

The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. This creates a cascading risk where a single malicious router can compromise the entire system, highlighting the need for greater security guarantees in the AI infrastructure.