Security researcher Chaofan Shou purchased a 6TB Fable dataset from a leading Chinese LLM router that provides access to 7 government entities and 19 major corporations. The leaked credentials include SSH keys, VPN configurations, Aliyun keys, and GitLab tokens used by companies such as Xiaomi, Huawei, NIO, and MiniMax. A related paper alleges 26 different LLM routers have secretly injected malicious tool calls to steal credentials, allowing the takeover of about 400 hosts within several hours and the draining of a $500,000 client wallet.
The breach targets a layer of the AI stack where third-party routers manage traffic between users and underlying model vendors. Exposed data also includes credentials for Bilibili, Xpeng, and Sangfor, while some targets include the University of Science and Technology of China and the Zhejiang Lab. Security experts suggest the incident highlights a need for ephemeral authentication systems as AI agents become more integrated into corporate workflows.
Key sources
- SOURCE@shoucccc“With just 6TB data, I can take over 7 Chinese/CIS gov entities & 19 top Chinese firms like Xiaomi, Huawei, NIO, Minimax”x.com
- SUPPORT@shoucccc“比如小鹏的阿里云凭证 bilibili的vpn+fawkes root 还有一堆”x.com
- SUPPORT@maxforai“包含大量企业和机构通过 Router 泄露出去的 SSH Key、VPN 配置、阿里云 Key、GitLab Token 等凭证”x.com
- SUPPORT@hrkrshnn“Auth needs to be rebuilt in the agent era. Everything needs to be ephemeral.”x.com
- SUPPORT@cpmou2022““third-party routers will own the customer” thesis just got a new risk factor”x.com