6TB leak from a Chinese LLM router exposes credentials to hijack Xiaomi, Huawei and gov entities

teortaxesTex · x · 2026-09-11

Security researcher @shoucccc revealed a severe data leak: he bought a "Fable" dataset from a top Chinese LLM router, and within just 6TB of data found SSH keys, VPN configs, Aliyun keys, and GitLab tokens sent to the router — enough to take over 7 Chinese/CIS government entities and 19 major Chinese firms including Xiaomi, Huawei, NIO and Minimax. @teortaxesTex amplified it, commenting that no Mythos-style cyberattack is needed. The incident highlights how LLM API routers aggregate highly sensitive credentials from user traffic.

Original post →

More from Safety

Safety channel →