26 LLM Routers Caught Injecting Malicious Tool Calls and Stealing Credentials, One Client Lost $500k

RexDouglass · x · 2026-09-11

An arXiv study systematically measures malicious LLM API routers: of 28 paid and 400 free routers tested, 9 actively injected code, 17 touched canary AWS credentials, one drained $500k in ETH, and poisoning experiments show benign routers can be compromised — leaking 99 credentials across 440 Codex sessions with billions of billed tokens.

Original post →

More from Infra

Infra channel →