The rapid growth of the cryptocurrency industry is driving the development of AI agents that can handle various tasks, from booking flights to making payments. However, a recent study suggests that the underlying infrastructure supporting this shift may be insecure. According to a report by McKinsey, AI agents are expected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Meanwhile, industry leaders such as Coinbase founder Brian Armstrong and Binance founder Changpeng Zhao predict that AI agents will soon outnumber humans in making transactions on the internet, with a significant portion of these transactions being crypto-based.

Nevertheless, a group of security academics and crypto researchers have identified a critical vulnerability in the AI infrastructure that could be exploited to steal sensitive data and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that so-called 'LLM routers' or services that connect users to AI models can be used as a powerful attack point by malicious actors. These routers have full access to all data passing through them, including sensitive information.

The researchers warned that users are extremely vulnerable to these attacks, as they often assume they are interacting directly with a reputable AI model when, in reality, their requests are passing through intermediary services that can see and modify their data. One of the researchers, Chaofan Shou, noted that the problem is no longer theoretical, citing an instance where a malicious router drained a client's $500,000 wallet. The researchers also demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.

As the industry continues to predict a growing share of crypto activity being handled by AI agents, the lack of guarantees that outputs haven't been tampered with poses a significant concern.