6TB leak from a Chinese LLM router exposes credentials to hijack Xiaomi, Huawei and gov entities
teortaxesTex · x · 2026-09-11
Security researcher @shoucccc revealed a severe data leak: he bought a "Fable" dataset from a top Chinese LLM router, and within just 6TB of data found SSH keys, VPN configs, Aliyun keys, and GitLab tokens sent to the router — enough to take over 7 Chinese/CIS government entities and 19 major Chinese firms including Xiaomi, Huawei, NIO and Minimax. @teortaxesTex amplified it, commenting that no Mythos-style cyberattack is needed. The incident highlights how LLM API routers aggregate highly sensitive credentials from user traffic.
More from Safety
- OpenAI Asks Congress Whether Coordinating an Industry-Wide AI Slowdown Would Be Legal — nordicinst · 2026-09-11
- Anthropic publishes its most detailed threat intel report on Claude misuse and disruptions — soumitrashukla9 · 2026-09-11
- Commentary: AI Safety Violations Pile Up as Regulation Keeps Trailing the Technology — AryHHAry · 2026-09-11
- Meta Details Muse Agent Safety: Sentinel Gate, Sandboxing and Human-in-the-Loop Protocol Approvals — altryne · 2026-09-11
- AI safety verification research should target commitments in frontier safety frameworks, researchers argue — HaydnBelfield · 2026-09-11
- Epoch AI data: China's top models trail US frontier by 6.3 months, real gap closer to 8 — deanwball · 2026-09-11