26 LLM Routers Caught Injecting Malicious Tool Calls and Stealing Credentials, One Client Lost $500k
RexDouglass · x · 2026-09-11
An arXiv study systematically measures malicious LLM API routers: of 28 paid and 400 free routers tested, 9 actively injected code, 17 touched canary AWS credentials, one drained $500k in ETH, and poisoning experiments show benign routers can be compromised — leaking 99 credentials across 440 Codex sessions with billions of billed tokens.
More from Infra
- PyTorch Lightning checkpointing runs up to 95% faster on Google Cloud — LightningAI · 2026-09-11
- Nearly 10% of exposed LiteLLM gateways accept default admin key 'sk-1234' — Thionne_WTZ · 2026-09-11
- K2 Horizon's frozen-model LoRA gives 3x faster inference, trained on 20T tokens — rohanpaul_ai · 2026-09-11
- DOJ probes Nvidia's $17B license-and-hire absorption of Grok rival Groq — Servola-Journal · 2026-09-11
- Nari Labs launches 50ms TTS endpoint, 10x cheaper than ElevenLabs on Qwen3-TTS — iamaliveix · 2026-09-11
- Amkor raises Arizona advanced packaging investment to $12B from $7B on surging demand — zephyr_z9 · 2026-09-11