The rapid growth of the cryptocurrency industry is driving the adoption of AI agents for various transactions, including payments and trades. According to a recent projection by McKinsey, AI agents may facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao estimating that agents will make millions of times more payments than people, all in crypto.

However, a group of security academics and crypto researchers has identified a significant vulnerability in the AI infrastructure that underpins this shift. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have released a paper highlighting the risks associated with so-called 'LLM routers.' These services act as intermediaries between users and AI models, forwarding requests to models like OpenAI or Anthropic. While designed to facilitate communication between users and AI models, LLM routers also have unrestricted access to sensitive data passing through them, making them a potential attack point for malicious actors. The researchers found that LLM routers can be exploited to steal credentials and even drain crypto wallets.

In one instance, a test Ethereum wallet was drained after its private key was exposed. The team also demonstrated how easily the attack can be expanded by 'poisoning' parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. This creates a significant risk, as a single malicious router in the chain can compromise the entire system, underscoring a weakest-link problem.

The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers warn that the industry's increasing reliance on AI agents for crypto transactions may be compromised by the lack of guarantees that the underlying infrastructure is secure.