The cryptocurrency sector is on the cusp of a revolution where AI agents will manage various tasks, including payments and transactions. However, recent research has raised concerns about the security of the underlying infrastructure. According to a McKinsey projection, AI agents may facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.

Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao forecasting that agents will make significantly more crypto payments than people. A group of security academics and crypto researchers has identified a vulnerability in a largely overlooked aspect of AI infrastructure, which has already been exploited to steal credentials and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, found that LLM routers, which act as intermediaries between users and AI models, can be used as powerful attack points.

These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which are often transmitted in plain text. The researchers demonstrated that a malicious router can replace benign commands with attacker-controlled ones or exfiltrate credentials without the user's knowledge. This vulnerability has severe implications for crypto users, as exposed credentials can be copied and reused without the user's knowledge. The researchers also showed that it is relatively easy to expand the attack by poisoning parts of the router ecosystem, potentially compromising hundreds of downstream systems within hours.

This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a weakest-link problem.