The crypto industry is rapidly moving towards an AI-driven future where agents will manage various tasks, including payments and transactions. However, a new research paper suggests that the underlying infrastructure may be vulnerable to security breaches. According to a McKinsey projection, AI agents could facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030.
Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber human users in making transactions on the internet, with Binance founder Changpeng Zhao estimating that agents will make one million times more payments than people, all in crypto. A group of security researchers and academics from the University of California, Santa Barbara, the University of California, San Diego, Fuzzland, and World Liberty Financial have identified a significant security flaw in the AI infrastructure.
The researchers found that LLM routers, which act as intermediaries between users and AI models, can be exploited by malicious actors to steal sensitive data, including credentials and crypto wallet information. These routers have full access to all data passing through them, making users extremely vulnerable to attacks. The researchers warn that a single malicious router can compromise an entire system, and the problem is no longer theoretical. In fact, one of the researchers, Chaofan Shou, reported that 26 LLM routers were found to be secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.
The researchers demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The study highlights a weakest-link problem, where a single malicious router in the chain can compromise the entire system, posing a significant risk to crypto users. As industry leaders predict that AI agents will handle a growing share of crypto activity, the underlying infrastructure lacks guarantees that outputs haven’t been tampered with, creating a potential mismatch.