Third-party AI routing services are exposing users to significant security flaws that could result in the theft of cryptocurrency and cloud credentials. AccordingThird-party AI routing services are exposing users to significant security flaws that could result in the theft of cryptocurrency and cloud credentials. According

UC researchers warn third-Party AI routers are stealing crypto and private keys

2026/04/13 17:36
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Third-party AI routing services are exposing users to significant security flaws that could result in the theft of cryptocurrency and cloud credentials.

Summary
  • Researchers found that 26 third-party LLM routers are actively injecting malicious code and stealing credentials by exploiting their access to plaintext data.
  • The study revealed that intermediaries can intercept private keys and cloud credentials because they terminate secure encryption to aggregate AI requests.

According to a paper published on Thursday by University of California researchers, the supply chain for Large Language Models (LLM) contains several vulnerabilities that allow for malicious code injection and credential extraction. 

These intermediaries, which developers use to manage access to providers like Google or OpenAI, essentially act as a “middleman” that terminates secure encryption. 

Because they have full plaintext access to every message sent through them, sensitive data like seed phrases or private keys can be intercepted by unverified infrastructure.

Evasion tactics and the “YOLO” risk

The researchers tested 400 free and 28 paid routers to measure the extent of these risks. Nine of these services actively injected malicious code, while 17 separate routers were caught accessing Amazon Web Services credentials owned by the team. 

During the experiment, one router successfully drained Ether from a decoy wallet after the researchers provided a prefunded private key. 

Although the team kept the balances low to ensure the total loss remained under $50, the result confirmed how easily a compromised intermediary can siphon funds.

“26 LLM routers are secretly injecting malicious tool calls and stealing creds,” co-author Chaofan Shou stated on X.

Identifying a malicious router is a difficult task for the average user. The researchers noted that because these services must read data to forward it, there is no visible difference between legitimate handling and active theft. 

The danger increases when developers enable “YOLO mode,” a setting in many AI frameworks that lets an agent execute commands automatically without a human confirming the action. 

This allows an attacker to send instructions that the user’s system will run instantly, often without the operator’s knowledge.

“The boundary between ‘credential handling’ and ‘credential theft’ is invisible to the client because routers already read secrets in plaintext as part of normal forwarding,” the study explained.

Previously reliable routers can become dangerous if they reuse leaked credentials through weak relays. To prevent these attacks, the research team suggested that developers should never allow private keys or sensitive phrases to pass through an AI agent session. 

A permanent solution would require AI companies to use cryptographic signatures. Such a system would allow an agent to mathematically prove that instructions came from the actual model rather than a tampered third-party source.

“LLM API routers sit on a critical trust boundary that the ecosystem currently treats as transparent transport,” the paper concluded.

시장 기회
Cloud 로고
Cloud 가격(CLOUD)
$0.02173
$0.02173$0.02173
+0.13%
USD
Cloud (CLOUD) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!