The crypto industry is rapidly advancing towards an AI-driven future, where automated agents will manage various tasks, including transactions and payments. However, a recent study reveals that the underlying infrastructure may be insecure. According to McKinsey, AI agents may facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.

Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making online transactions, with Binance founder Changpeng Zhao forecasting that agents will make millions of times more crypto payments than people. Nevertheless, a group of security experts and crypto researchers have identified a critical flaw in the AI infrastructure that can be exploited to steal sensitive information and drain crypto wallets. The researchers, affiliated with the University of California and other institutions, found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have unrestricted access to sensitive data, including private keys, API credentials, and wallet access tokens.

The researchers warn that a single compromised router can compromise the entire system, highlighting a significant weakest-link problem. They demonstrated how easily an attack can be expanded by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.

The implications for crypto users are severe, as exposed credentials can be reused without their knowledge, and the researchers found multiple instances of routers collecting sensitive information. The study's findings suggest a potential mismatch between the increasing use of AI agents in crypto transactions and the lack of guarantees that the underlying infrastructure is secure.