Measuring Malicious Intermediary Attacks on the LLM Supply Chain A study of 26 LLM routers found that the routers secretly inject malicious tool calls and steal credentials, according to the paper's authors, who said they bought a Fable dataset from a top Chinese LLM router and used 6TB of data to compromise SSH keys, VPN configs, Aliyun keys, and GitLab tokens belonging to 7 Chinese/CIS government entities and 19 top Chinese firms including Xiaomi, Huawei, NIO, and Minimax. The researchers said one router drained a client's $500,000 wallet and that poisoned routers let them take over roughly 400 hosts within several hours. I bought a Fable dataset from one of the top Chinese LLM routers yesterday. With just 6TB data, I can take over 7 Chinese/CIS gov entities & 19 top Chinese firms like Xiaomi, Huawei, NIO, Minimax using SSH keys, VPN configs, Aliyun keys, GitLab tokens sent to the router. 26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet. We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts. Check our paper: