---
format: "aidr-story-markdown/v1"
id: "8ba53b7711aeb859bdd63881d9f2e7de82356e798b573d504673d87ffa4b1616"
canonical_url: "https://aidr.today/8ba53b77?lang=en"
title: "LLM Router Leak Exposes 19 Top Chinese Firms and 7 Government Entities"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-11T05:47:35.000Z"
category: "Industry"
topics: ["llm","security","infra","china"]
source_urls: ["https://huggingnews.com/cybersecurity/llm-router-leak-exposes-19-top-chinese-firms-and-7-government-entities-43f34043","https://x.com/shoucccc/status/2098169782541631871","https://x.com/shoucccc/status/2098236184904520017","https://x.com/MaxForAI/status/2098252309730038268","https://x.com/hrkrshnn/status/2098218543133135214","https://x.com/CPMou2022/status/2098261177302434210"]
summary: "Security researcher Chaofan Shou purchased a 6TB Fable dataset from a leading Chinese LLM router that provides access to 7 government entities and 19 major corporations. The leaked credentials include SSH keys, VPN configurations, Aliyun keys, and GitLab tokens used by companies such as Xiaomi, Huawei, NIO, and MiniMax. A related paper alleges 26 different LLM routers have secretly injected malicious tool calls to steal credentials, allowing the takeover of about 400 hosts within several hours and the draining of a $500,000 client wallet. The breach targets a layer of the AI stack where third-party routers manage traffic between users and underlying model vendors. Exposed data also includes credentials for Bilibili, Xpeng, and Sangfor, while some targets include the University of Science and Technology of China and the Zhejiang Lab. Security experts suggest the incident highlights a need for ephemeral authentication systems as AI agents become more integrated into corporate workflows."
---

# LLM Router Leak Exposes 19 Top Chinese Firms and 7 Government Entities

> [Open the canonical story](<https://aidr.today/8ba53b77?lang=en>)

**Published:** 2026-09-11T05:47:35.000Z
**Category:** Industry
**Topics:** llm, security, infra, china

## Summary

Security researcher Chaofan Shou purchased a 6TB Fable dataset from a leading Chinese LLM router that provides access to 7 government entities and 19 major corporations\. The leaked credentials include SSH keys, VPN configurations, Aliyun keys, and GitLab tokens used by companies such as Xiaomi, Huawei, NIO, and MiniMax\. A related paper alleges 26 different LLM routers have secretly injected malicious tool calls to steal credentials, allowing the takeover of about 400 hosts within several hours and the draining of a $500,000 client wallet\. The breach targets a layer of the AI stack where third\-party routers manage traffic between users and underlying model vendors\. Exposed data also includes credentials for Bilibili, Xpeng, and Sangfor, while some targets include the University of Science and Technology of China and the Zhejiang Lab\. Security experts suggest the incident highlights a need for ephemeral authentication systems as AI agents become more integrated into corporate workflows\.

## Sources

- [Story source](<https://huggingnews.com/cybersecurity/llm-router-leak-exposes-19-top-chinese-firms-and-7-government-entities-43f34043>)
- [Story source](<https://x.com/shoucccc/status/2098169782541631871>)
- [Supporting source](<https://x.com/shoucccc/status/2098236184904520017>)
- [Supporting source](<https://x.com/MaxForAI/status/2098252309730038268>)
- [Supporting source](<https://x.com/hrkrshnn/status/2098218543133135214>)
- [Supporting source](<https://x.com/CPMou2022/status/2098261177302434210>)

