The crypto industry is on the cusp of a revolution where AI agents manage transactions, trades, and payments, but recent findings suggest that the underlying infrastructure may be flawed. According to McKinsey, AI agents could facilitate $3 trillion to $5 trillion in global consumer commerce by 2030.

However, a team of security academics and crypto researchers has discovered that a largely overlooked aspect of AI infrastructure is being exploited to steal credentials and drain crypto wallets. The researchers found that 'LLM routers,' which act as intermediaries between users and AI models, can be used as a powerful attack point by malicious actors. These routers have full access to sensitive data, including private keys, API credentials, and wallet access tokens, leaving users vulnerable to theft. The problem is no longer theoretical, with one researcher reporting that 26 LLM routers are secretly injecting malicious tool calls and stealing credentials, resulting in a $500,000 wallet drain.

The researchers warn that a single malicious router can compromise an entire system, highlighting a weakest-link problem that threatens the security of crypto payments.