The cryptocurrency sector is rapidly moving towards an AI-driven future, where automated agents will manage various transactions, including payments and trades. However, recent studies suggest that the underlying infrastructure supporting this shift may be insecure. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Meanwhile, industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict that AI agents will soon surpass humans in making transactions on the internet, with the latter expecting agents to make one million times more payments than people, all in crypto. Nevertheless, a group of security academics and crypto researchers have identified a critical flaw in the AI infrastructure, which can be exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that LLM routers, which act as intermediaries between users and AI models, can be used as powerful attack points by malicious actors.
These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be stolen or modified. The researchers warned that a single malicious router in the chain can compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.
This vulnerability has already been linked to stolen credentials and a $500,000 wallet drain, highlighting the need for increased security measures to protect crypto users.