2026-10-11 17:15 UTC

Chaofan Shou and the authors of “Your Agent Is Mine” claim third-party LLM routers inject malicious code and expose actionable credentials, with Shou reporting a newly purchased 6TB dataset, making router selection a direct host-compromise and secret-exposure risk for agent deployments.

state: watchingheat: lowuncertainty: highconvergesscott: highllm-supply-chain agentic-security api-routers credential-exposureChaofan ShouHanzhi LiuHongbo WenYanju ChenRyan Jingyang FangYu Feng
Surfaced 2026-09-11T07:28:55Z — priced heat=high at create: Chaofan Shou and the authors of “Your Agent Is Mine” claim third-party LLM routers inject malicious code and expose actionable credentials, with Shou reporting a newly purchased 6TB dataset, making router selection a direct host-compromise and secret-exposure risk for agent deployments.

What is this?

“Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain” is a research paper attributed by one supplied snippet to UCSB, UCSD, and collaborators, examining third-party routers as an attack surface for LLM agents. A secondary news report describes router-poisoning experiments involving researcher-controlled keys and router decoys, reporting credential exposure in downstream Codex sessions, many with tool execution auto-approved. These snippets support concern about intermediary trust and agent credential handling, but do not independently establish the case’s named authors, the 28-paid/400-free router sample, Shou’s reported 6TB purchase, or demonstrated host compromise.

Why it matters to Scott

The reported router-poisoning experiments converge with Scott’s Agent Provenance Stack and SiloOS separation of model output from authorised execution, and warrant reviewing Ask’s response-to-shell dispatch and merely behavioural approval gate behind his LAN LiteLLM proxy—not evidence that his proxy is compromised. The radar’s llm-api-reseller-dependency-risks page tracks adjacent intermediary risks, not these experiments; the supplied grounding does not establish demonstrated host compromise, the claimed sample size or the 6TB purchase.
ip:framework.agent-provenance-stackip:framework.siloosdev:project.askdev:technology.litellmradar:llm-api-reseller-dependency-risksradar:coding-agent-approval-threat-missesradar:concept.model-provenanceradar:concept.credential-isolation
queries asked of Scott's wikis
  • coding agent harness trust boundaries third-party API routers
  • LLM supply chain response integrity malicious intermediaries
  • agent tool auto-approval sandboxing host execution
  • agent secret isolation credential exposure API key handling
  • model routing provider provenance local inference security

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 4466h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

04-08 14:00⭐ origin echo-reconstructedThe authors report studying 28 paid and 400 free LLM routers, finding malicious code injection, access to researcher-owned canary credential
Hanzhi Liu, Chaofan Shou, Hongbo Wen, Yanju Chen, Ryan Jingyang Fang, Yu Feng on paper (echo) · attributed from hn.story.49654448, hn.story.49654427
—
09-09 05:37first on hacker news · published · +3687.6hSo you want to use OpenRouter?
player85
—
09-14 03:12first on r/ClaudeAI · published · +3805.2h[Investigation] The "Unlimited Compute" Scam: Wire-Level Proof of Model Spoofing, Dangerous Setup Scripts, and Packet Analysis of CodexAPI.pro
Itchy_Analyst_7369
—
09-09 05:37amplified on hacker news 👑hn.story.49621546
player85
peak 766 · 206 comments · 99% of case engagement
09-11 06:50amplified on hacker newshn.story.49654427
0in
peak 2 · 0 comments · 0% of case engagement
09-11 06:52amplified on hacker newshn.story.49654448
soltanov
peak 1 · 0 comments · 0% of case engagement
09-14 03:12amplified on r/ClaudeAIreddit.post.1wfrwb6
Itchy_Analyst_7369
peak 3 · 12 comments · 1% of case engagement
09-11 07:21our radar first saw it · +3737.4hdiscovery anchor: hn.story.49654448—
09-11 07:23reached heat=high · +3737.4h · via ledger——

Evidence (5) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnMeasuring Malicious Intermediary Attacks on the LLM Supply Chain
Retrieved article excerpt

Open article · Retrieved 2026-09-11T07:23:01.373311+00:00

Chaofan Shou @shoucccc I bought a Fable dataset from one of the top Chinese LLM routers yesterday. 

With just 6TB data, I can take over 7 Chinese/CIS gov entities & 19 top Chinese firms like Xiaomi, Huawei, NIO, Minimax using SSH keys, VPN configs, Aliyun keys, GitLab tokens sent to the router. Chaofan Shou @shoucccc Apr 10 26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.

We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts. 

Check our paper: arxiv.org/abs/2604.08407 10:00 PM · Sep 10, 2026 1.2M Views 135 424 4.5K 3K
soltanov10
🟧 hnMeasuring Malicious Intermediary Attacks on the LLM Supply Chain
Retrieved article excerpt

Open article · Retrieved 2026-09-11T07:23:02.348035+00:00

Computer Science > Cryptography and Security arXiv:2604.08407 (cs) [Submitted on 9 Apr 2026] Title: Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain Authors: Hanzhi Liu , Chaofan Shou , Hongbo Wen , Yanju Chen , Ryan Jingyang Fang , Yu Feng View a PDF of the paper titled Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain, by Hanzhi Liu and 5 other authors View PDF HTML (experimental) Abstract: Large language model (LLM) agents increasingly rely on third-party API routers to dispatch tool-calling requests across multiple upstream providers. These routers operate as application-layer proxies with full plaintext access to every in-flight JSON payload, yet no provider enforces cryptographic integrity between client and upstream model. We present the first systematic study of this attack surface. We formalize a threat model for malicious LLM API routers and define two core attack classes, payload injection (AC-1) and secret exfiltration (AC-2), together with two adaptive evasion variants: dependency-targeted injection (AC-1.a) and conditional delivery (AC-1.b). Across 28 paid routers purchased from Taobao, Xianyu, and Shopify-hosted storefronts and 400 free routers collected from public communities, we find 1 paid and 8 free routers actively injecting malicious code, 2 deploying adaptive evasion triggers, 17 touching researcher-owned AWS canary credentials, and 1 draining ETH from a researcher-owned private key. Two poisoning studies further show that ostensibly benign routers can be pulled into the same attack surface: a leaked OpenAI key generates 100M GPT-5.4 tokens and more than seven Codex sessions, while weakly configured decoys yield 2B billed tokens, 99 credentials across 440 Codex sessions, and 401 sessions already running in autonomous YOLO mode. We build Mine, a research proxy that implements all four attack classes against four public agent frameworks, and use it to evaluate three deployable client-side defenses: a fail-closed policy gate, response-side anomaly screening, and append-only transparency logging. Subjects: Cryptography and Security (cs.CR) Cite as: arXiv:2604.08407 [cs.CR] (or arXiv:2604.08407v1 [cs.CR] for this version) https://doi.org/10.48550/arXiv.2604.08407 Focus to learn more arXiv-issued DOI via DataCite Submission history From: Yanju Chen [ view email ] [v1] Thu, 9 Apr 2026 16:06:41 UTC (54 KB) Full-text links: Access Paper: View a PDF of the paper titled Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain, by Hanzhi Liu and 5 other authors View PDF HTML (experimental) TeX Source view license Current browse context: cs.CR < prev | next > new | recent | 2026-04 Change to browse by: cs References & Citations NASA ADS Google Scholar Semantic Scholar export BibTeX citation Loading... BibTeX formatted citation × loading... Data provided by: Bookmark Bibliographic Tools Bibliographic and Citation Tools Bibliographic Explorer Toggle Bibliographic Explorer ( What is the Explorer? ) Connected Papers Toggle Connected Papers ( What is Connected Papers? ) Litmaps Toggle Litmaps ( What is Litmaps? ) scite.ai Toggle scite Smart Citations ( What are Smart Citations? ) Code, Data, Media Code, Data and Media Associated with this Article alphaXiv Toggle alphaXiv ( What is alphaXiv? ) Links to Code Toggle CatalyzeX Code Finder for Papers ( What is CatalyzeX? ) DagsHub Toggle DagsHub ( What is DagsHub? ) GotitPub Toggle Gotit.pub ( What is GotitPub? ) Huggingface Toggle Hugging Face ( What is Huggingface? ) ScienceCast Toggle ScienceCast ( What is ScienceCast? ) Demos Demos Replicate Toggle Replicate ( What is Replicate? ) Spaces Toggle Hugging Face Spaces ( What is Spaces? ) Spaces Toggle TXYZ.AI ( What is TXYZ.AI? ) Related Papers Recommenders and Search Tools Link to Influence Flower Influence Flower ( What are Influence Flowers? ) Core recommender toggle CORE Recommender ( What is CORE? ) Author Venue Institution Topic About arXivLabs arXivLabs: experimental projects with community collaborators arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website. Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them. Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs . Which authors of this paper are endorsers? | Disable MathJax ( What is MathJax? )
0in20
🟧 echo.paper ⭐The authors report studying 28 paid and 400 free LLM routers, finding malicious code injection, access to researcher-owned canary credentialHanzhi Liu, Chaofan Shou, Hongbo Wen, Yanju Chen, Ryan Jingyang Fang, Yu Feng——
🟧 hnSo you want to use OpenRouter?player85766206
🟠 reddit[Investigation] The "Unlimited Compute" Scam: Wire-Level Proof of Model Spoofing, Dangerous Setup Scripts, and Packet Analysis of CodexAPI.pro
ClaudeAI
Itchy_Analyst_7369212

Interpretation history

Decision trace