The cryptocurrency sector is on the cusp of a revolution, with AI agents poised to take over various tasks, from booking flights to facilitating transactions and making payments. However, a recent study suggests that the underlying infrastructure may be insecure.

According to a McKinsey projection, AI agents could mediate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, while Binance founder Changpeng Zhao forecasts that agents will make a million times more payments than people, all in crypto. Nevertheless, a team of security academics and crypto researchers has released a paper highlighting a significant vulnerability in the AI infrastructure that could be exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors.

These routers have full access to sensitive data, including credentials and financial information, and can modify or steal this data without the user's knowledge. The researchers found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, with one instance resulting in the draining of a $500,000 wallet. The problem is exacerbated by the fact that these systems can operate autonomously, approving and executing actions without human review, making it possible for a single altered instruction to compromise systems or funds. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.

The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The team warns that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that could have significant consequences for the cryptocurrency industry.