The crypto industry is moving towards an AI-driven future where agents manage transactions, trades, and payments, but researchers warn that the underlying infrastructure may be insecure. According to a recent projection by McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.

However, a group of security researchers has identified a critical flaw in the AI infrastructure that could expose sensitive data, including crypto wallets. The researchers found that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors to steal credentials and drain crypto wallets.

These routers have full access to user data, including sensitive information, and can modify it without detection. The researchers demonstrated that a single malicious router can compromise an entire system, and they were able to drain a test Ethereum wallet by exposing its private key. The implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers warn that the lack of security guarantees in the AI infrastructure could lead to a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.