The cryptocurrency sector is rapidly moving towards an AI-driven future, where intelligent agents manage various transactions, including payments and trades. However, a new study suggests that the underlying infrastructure supporting this shift may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, while Binance founder Changpeng Zhao forecasts that agents will make one million times more crypto payments than people.

A group of security academics and crypto researchers have published a paper highlighting the risks associated with a largely overlooked aspect of AI infrastructure, which has already been linked to credential theft and crypto wallet drains. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, identified 'LLM routers' as a critical attack point.

These services, designed to forward requests to AI models like OpenAI or Anthropic, have full access to sensitive data passing through them. The researchers found that these routers can act as powerful attack points, exploited by malicious actors, leaving users vulnerable to data breaches and financial losses. The problem is no longer theoretical, as one of the researchers, Chaofan Shou, reported that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.

The researchers demonstrated how a single malicious router can compromise an entire system, highlighting a weakest-link problem. This creates a potential mismatch between the growing use of AI agents in crypto transactions and the lack of guarantees that the underlying infrastructure is secure. The study's findings have severe implications for crypto users, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text, making them vulnerable to theft and misuse.