Researchers find 26 LLM routers injecting malicious tool calls, one drained a client's $500k wallet
matthew_d_green · x · 2026-09-13
Security researchers (@shoucccc et al.) published a paper exposing supply-chain risks in LLM routers:
- They detected 26 LLM routers secretly injecting malicious tool calls and stealing credentials; one already drained a client wallet of $500k.
- They also poisoned routers to forward traffic to themselves, demonstrating they could take over 400 hosts within hours.
- Cryptographer @dinodaizovi amplified the finding: any inference API's responses can inject tool calls that your harness/agent may execute — a persistent attack surface to guard against.
Paper linked in the original post.
More from Safety
- Security researcher lays out 11-step path to a self-replicating AI botnet stealing API keys — joshua_saxe · 2026-09-14
- Pay-for-a-Paper? Fastcode AI packs a $100K contract into a conference publication — maier_ak · 2026-09-14
- AI safety researcher lays out how a self-replicating agent botnet could hijack inference providers — joshua_saxe · 2026-09-14
- GPT-6 Astra: 1M-token context, 2.5x price, and a 'Critical' cyber risk rating — Thirumalaivasan_GJ · 2026-09-14
- Sam Altman lays out the two ways AI progress could go badly wrong: losing control and power concentration — sama · 2026-09-14
- Open Letter to Amodei and Altman Challenges Frontier AI Slowdown Calls: State Keeps Moving — AryHHAry · 2026-09-14