The cryptocurrency sector is rapidly adopting AI agents to manage various tasks, including transactions and payments, but recent research reveals a significant security concern in the underlying infrastructure. According to a McKinsey projection, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a group of security researchers and academics has identified a largely overlooked vulnerability in AI infrastructure that can be exploited to steal credentials and drain crypto wallets.

The researchers found that LLM routers, which act as intermediaries between users and AI models, can be used as attack points by malicious actors. These routers have unrestricted access to sensitive data, including private keys and API credentials, making users extremely vulnerable to attacks. The researchers demonstrated the severity of the issue by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours.

This highlights a cascading risk, where a single malicious router can compromise the entire system, underscoring the need for increased security measures in AI infrastructure.