The cryptocurrency industry is on the verge of a significant shift, with AI agents poised to manage various tasks, including transactions and payments. However, recent research has uncovered a potential security flaw in the underlying infrastructure that supports this shift.

According to a report by McKinsey, AI agents may facilitate $3 trillion to $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao estimating that agents will make one million times more payments than people, all in crypto. Nevertheless, a group of security academics and crypto researchers have identified a largely overlooked vulnerability in AI infrastructure that can be exploited to steal credentials and drain crypto wallets.

The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have released a paper detailing their findings. They discovered that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be exploited to compromise systems or funds.

The researchers found that 26 LLM routers were secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain. They also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The team warned that a single malicious router in the chain is enough to compromise the entire system, creating a cascading risk that even if a user trusts their AI provider, the infrastructure in between may not be trustworthy.