University of California researchers have uncovered a critical security flaw in third-party LLM routers that allows for the theft of private keys and credentials. The findings highlight the dangers of unverified intermediary infrastructure in the AI supply chain.
- 26 LLM routers found stealing credentials and injecting code
- Plaintext access at TLS termination points enables data theft
- YOLO mode enables automatic execution of malicious commands
- 17 routers successfully accessed AWS credentials during testing
- Experts urge the adoption of cryptographic response signing
Sign up free to read the full analysis
Create a free account to unlock full AI-curated market articles, personalized alerts, and more.