The cryptocurrency sector is rapidly adopting AI agents to manage transactions, trades, and payments, but recent research reveals that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a team of security academics and crypto researchers has identified a significant vulnerability in the AI infrastructure, which can be exploited to steal credentials and drain crypto wallets.

The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as powerful attack points by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, making users extremely vulnerable to attacks. The researchers demonstrated that a single malicious router can compromise the entire system, and they were able to observe and potentially control hundreds of downstream systems within hours by poisoning parts of the router ecosystem. This highlights a weakest-link problem, where a single vulnerable point in the chain can compromise the entire system, emphasizing the need for guarantees that outputs haven't been tampered with.