The crypto industry is on the cusp of a revolution where AI agents manage transactions, trades, and payments, but a new study reveals that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. However, a team of security academics and crypto researchers has identified a largely overlooked vulnerability in AI infrastructure that can intercept sensitive data, including private keys, API credentials, and wallet access tokens.

This weakness, known as 'LLM routers,' allows malicious actors to steal credentials and drain crypto wallets. The researchers found that these routers can act as a powerful attack point, with 26 routers secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. The problem is exacerbated by the fact that these systems can operate autonomously, approving and executing actions without human review, making it easier for a single altered instruction to compromise systems or funds.

The researchers demonstrated how easy it is to expand the attack by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a cascading risk, where even if a user trusts their AI provider, the infrastructure in between may not be trustworthy, highlighting a weakest-link problem that could have severe implications for crypto users.