The cryptocurrency sector is on the cusp of a revolution, with AI agents poised to manage a wide range of tasks, from flight bookings to trade executions and payments. However, a recent study has uncovered a significant security risk in the underlying infrastructure that supports this shift. According to a report by McKinsey, AI agents are projected to facilitate between $3 trillion and $5 trillion in global consumer commerce by 2030. Coinbase founder Brian Armstrong has predicted that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao forecasting that agents will make over a million times more payments than people, all in crypto.

Nevertheless, a team of security academics and crypto researchers has identified a critical vulnerability in the AI infrastructure that could be exploited by malicious actors to steal sensitive data and drain crypto wallets. The researchers, affiliated with the University of California, Santa Barbara, the University of California, San Diego, blockchain firm Fuzzland, and World Liberty Financial, have published a paper detailing their findings. The study reveals that so-called LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to all data passing through them, including sensitive information.

The researchers warn that users are extremely vulnerable to these attacks, as they often assume they are interacting directly with a reputable AI model when, in reality, their requests are being routed through intermediary services that can modify or steal their data. One of the researchers, Chaofan Shou, has confirmed that the problem is no longer theoretical, stating that 26 LLM routers have been found to be secretly injecting malicious tool calls and stealing credentials, with one incident resulting in the draining of a client's $500,000 wallet. The researchers have demonstrated how a malicious router can replace a benign command with an attacker-controlled one or silently exfiltrate every credential that passes through it.

The implications for crypto users are severe, as private keys, API credentials, and wallet access tokens often pass through these systems in plain text. The researchers have found multiple cases where routers have collected these secrets, and in one instance, a test Ethereum wallet was drained after its private key was exposed. The team has also shown how easy it is to expand the attack by poisoning parts of the router ecosystem, allowing them to observe and potentially control hundreds of downstream systems within hours. The researchers conclude that a single malicious router in the chain is enough to compromise the entire system, highlighting a weakest-link problem that creates a potential mismatch between the growing use of AI agents in crypto activity and the lack of guarantees that the underlying infrastructure is secure.