Dongcha Beating AI News: Security researcher Shou Chaofan stated that he recently purchased approximately 6TB of Fable model invocation data from a Chinese leading large model intermediary. The data contained sensitive credentials such as SSH keys, VPN configurations, Alibaba Cloud keys, and GitLab tokens. He noted that the keys in this dataset were sufficient to grant access to the servers or internal systems of 19 leading Chinese enterprises and seven Chinese and CIS government-related institutions, including Huawei, Xiaomi, NIO, and MiniMax. Large model intermediaries sit between users and models like Claude, routing all requests and responses, thereby gaining access to full plaintext. When developers embed SSH keys, API keys, or VPN configurations into an agent’s context, if the intermediary stores or even sells these records, corporate system credentials are also exposed. This is not the first time Shou Chaofan has warned of risks posed by intermediaries. In a paper he co-authored in April, his team tested 428 LLM intermediaries and found that nine actively injected malicious code, 17 used AWS test keys deliberately inserted by researchers to make actual AWS calls, and one directly transferred ETH from a test wallet. Shou Chaofan is a co-founder of the blockchain security firm Fuzzland and has long focused on vulnerability and supply chain security research. At the end of March, he was the first to discover that the source map in the Claude Code 2.1.88 release package inadvertently exposed approximately 500,000 lines of TypeScript source code.
Security researcher warns that 6TB model relay data exposes keys to 19 major Chinese firms.
MarsBitShare
Security researcher Shou Chaofan uncovered a significant risk-to-reward ratio issue after acquiring 6TB of Fable model relay data, exposing SSH keys, Alibaba Cloud credentials, and GitLab tokens linked to 19 major Chinese companies and seven government-affiliated entities. These credentials could enable access to internal systems, revealing a critical support and resistance point in model relay security. Shou previously tested 428 LLM relay stations, discovering malicious code injections and unauthorized AWS access. His findings highlight the urgent need for stronger security protocols in relay infrastructure.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.