The cryptocurrency sector is on the cusp of a revolution where AI agents will manage various tasks, including transactions and payments, but a recent study reveals that the underlying infrastructure may be flawed. According to a McKinsey projection, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.

Coinbase founder Brian Armstrong predicts that AI agents will soon outnumber humans in making internet transactions, with Binance founder Changpeng Zhao estimating that agents will make a million times more crypto payments than people. However, a group of researchers has identified a critical vulnerability in a largely overlooked aspect of AI infrastructure, which has already been exploited to steal credentials and drain crypto wallets.

The researchers, affiliated with the University of California and other institutions, found that LLM routers, which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, which are often transmitted in plain text. The researchers demonstrated that a single malicious router can compromise an entire system, allowing hackers to replace benign commands with malicious ones or exfiltrate credentials without detection.

They also showed that it is possible to 'poison' parts of the router ecosystem, allowing them to observe and control hundreds of downstream systems within hours. The implications for crypto users are severe, as exposed credentials can be reused without the user's knowledge, and the researchers found multiple cases where routers collected sensitive information. The study highlights a weakest-link problem, where a single vulnerable router can compromise the entire system, even if the user trusts their AI provider. As industry leaders predict that AI agents will handle a growing share of crypto activity, the lack of guarantees that outputs haven't been tampered with creates a potential mismatch, underscoring the need for enhanced security measures to protect users.