The cryptocurrency sector is moving towards an AI-driven future, where agents will manage various tasks, including transactions and payments. However, a recent study highlights a significant security flaw in the underlying infrastructure, which could put users' sensitive data at risk.

According to researchers from the University of California and other institutions, a type of AI infrastructure known as LLM routers can intercept and modify sensitive information, including private keys and API credentials. These routers act as intermediaries between users and AI models, but they can also be exploited by malicious actors to steal sensitive data. The researchers found that several LLM routers are already being used for malicious purposes, including stealing credentials and draining crypto wallets. In one instance, a test Ethereum wallet was drained after its private key was exposed.

The implications of this vulnerability are severe, as it could allow malicious actors to compromise systems and funds without being detected. The researchers warn that the lack of security guarantees in the underlying infrastructure could create a mismatch between the growing use of AI agents in crypto transactions and the potential risks associated with it.