The cryptocurrency industry is moving towards a future where AI agents manage various tasks, including payments and trades, but recent research indicates that the underlying infrastructure may be insecure. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion of global consumer commerce by 2030. Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making transactions on the internet, with Binance founder Changpeng Zhao forecasting that agents will make one million times more payments than people, all in crypto. However, a group of security academics and crypto researchers have published a paper highlighting that a largely overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets.

The researchers, affiliated with the University of California and blockchain firm Fuzzland, found that LLM routers, which sit between users and AI models, can be a powerful attack point for malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which can be intercepted and used to compromise systems or funds. The researchers demonstrated that a single malicious router can replace benign commands with attacker-controlled ones or exfiltrate credentials, and that the problem is no longer theoretical, with 26 LLM routers found to be secretly injecting malicious tool calls and stealing credentials.

The implications for crypto users are severe, with private keys, API credentials, and wallet access tokens often passing through these systems in plain text. The researchers found multiple cases where routers collected these secrets, including an instance where a test Ethereum wallet was drained after its private key was exposed.

The team also demonstrated how easy it is to expand the attack by poisoning parts of the router ecosystem, which could potentially control hundreds of downstream systems within hours. The researchers conclude that the infrastructure underlying AI-powered crypto payments lacks guarantees that outputs haven't been tampered with, creating a potential mismatch between the growing use of AI agents and the security of the underlying infrastructure.