The crypto industry is on the verge of a significant shift, with AI agents poised to manage a wide range of tasks, from flight bookings to trade executions and payments. However, recent findings suggest that the underlying infrastructure may not be as secure as initially thought. A report by McKinsey estimates that AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Brian Armstrong, founder of Coinbase, predicts that AI agents will soon outnumber humans in making online transactions, while Binance founder Changpeng Zhao forecasts that agents will make millions of times more payments than people, all in crypto.

Nevertheless, a team of security researchers and academics has uncovered a critical flaw in the AI infrastructure that could expose wallets to significant risks. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have identified a vulnerability in 'LLM routers,' which are services that connect users to AI models like OpenAI or Anthropic.

These routers have full access to all data passing through them, including sensitive information, and can be exploited by malicious actors. The researchers warn that users are extremely vulnerable as they assume they are interacting directly with a reputable AI model, when in reality, many requests pass through intermediary services that can see and modify the data. According to Chaofan Shou, one of the researchers, the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The researchers also demonstrated how a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it.

For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers found multiple cases where routers collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed.

The team also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers conclude that a single malicious router in the chain is enough to compromise the entire system, highlighting a weakest-link problem that creates a potential mismatch between the growing reliance on AI agents and the lack of guarantees that the underlying infrastructure is secure.