The cryptocurrency sector is rapidly moving towards an AI-driven future where agents will manage various tasks, including transactions and payments. However, recent research suggests that the underlying infrastructure may be insecure.

According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao forecasting that agents will make a million times more crypto payments than people. A group of security academics and crypto researchers have published a paper highlighting a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets.

The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, discovered that 'LLM routers' or services that connect users to AI models can be powerful attack points for malicious actors. These routers have full access to all data passing through them, including sensitive information.

The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain. A malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it.

The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a potential mismatch between the growing use of AI agents in crypto activity and the lack of guarantees that outputs haven’t been tampered with.