The cryptocurrency sector is moving towards an AI-driven future where agents manage various tasks, including transactions and payments, but research indicates that the underlying infrastructure may be insecure. A report by McKinsey estimates that AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.

However, a group of security researchers and academics have identified a largely overlooked AI infrastructure component that is being exploited to steal credentials and drain crypto wallets. The vulnerability lies in 'LLM routers,' which act as intermediaries between users and AI models, having full access to sensitive data passing through them. These routers can be used as powerful attack points by malicious actors, leaving users vulnerable as they assume they are interacting directly with reputable AI models. The researchers found that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, with one instance resulting in a $500,000 wallet drain.

The problem is exacerbated by the autonomous nature of these systems, which can approve and execute actions without human review, allowing a single altered instruction to compromise systems or funds. For crypto users, the implications are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text.

The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where a single malicious router in the chain can compromise the entire system, highlighting a weakest-link problem in the infrastructure.