Research: 26 LLM routers are secretly injecting malicious tool calls and stealing credentials.

PANews reported on April 10th that Chaofan Shou, a member of the Solayer team, published an article on the X platform stating that 26 LLM routers were secretly injecting malicious tools to call and steal credentials. One of these routers had already caused its customer to lose $500,000 in wallets. Researchers also successfully performed a "poisoning" attack on the router, causing it to forward traffic to itself, directly taking over approximately 400 hosts within hours. This is consistent with the team's previous research paper, revealing a significant security threat posed by third-party LLM API routers to proxy systems.

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
South Korea's Financial Intelligence Service plans to tighten rules on transfers between personal wallets and overseas exchanges.
PANews Newsflash