Paper: 26 malicious LLM routers inject tool calls, steal keys, drain $500k

petrusenko_max · x · 2026-09-22

An arXiv paper, "Your Agent Is Mine," presents the first systematic study of malicious LLM API routers. Agents route tool calls through third-party proxies with full plaintext access, with no cryptographic integrity between client and upstream model.

A serious wake-up call for developers using third-party API routers or relays.

Original post →

More from coding & agent

coding & agent channel →