Researchers have identified a critical security flaw in third-party AI routers that allows attackers to steal private keys and inject malicious code. The study warns that developers using AI agents for smart contract coding are particularly at risk.
- 26 LLM routers identified as malicious or credential-stealing
- TLS termination allows intermediaries to read private keys in plaintext
- 9 routers injected malicious code; 17 accessed AWS credentials
- Automatic execution settings ('YOLO mode') increase attack success rates
- Experts recommend cryptographic signing of AI responses for verification
Sign up free to read the full analysis
Create a free account to unlock full AI-curated market articles, personalized alerts, and more.