The cryptocurrency sector is rapidly moving towards an AI-driven future, where artificial intelligence agents will manage various tasks, including payments and transactions. However, a recent study suggests that the underlying infrastructure may be insecure. According to McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, while Binance founder Changpeng Zhao forecasts that agents will make one million times more payments than people, all in crypto.

A group of security academics and crypto researchers have released a paper highlighting the risks associated with a largely overlooked piece of AI infrastructure, which can be exploited by malicious actors to steal credentials and drain crypto wallets. The researchers found that LLM routers, or services that connect users to AI models, can act as a powerful attack point. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and modified.

The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The study suggests that a single malicious router in the chain can compromise the entire system, highlighting a weakest-link problem. This creates a potential mismatch between the growing use of AI agents in crypto activity and the lack of guarantees that the underlying infrastructure is secure.