🤦 6TB of data exchanged for credentials of 19 top enterprises: Leakage of Xiaomi, Huawei, NIO credentials via leading Chinese LLM intermediary This is a major security incident involving the large-scale leakage of enterprise and government credentials through LLM intermediaries (routers). Chaofan Shou @shoucccc posted that he purchased a dataset called the “Fable dataset” (approximately 6TB) from a leading Chinese LLM intermediary. From this dataset alone, he extracted a vast number of real credentials, including SSH keys, VPN configurations, Alibaba Cloud keys, and GitLab tokens. He claims these credentials are sufficient to take over seven Chinese/CIS government entities and 19 top Chinese enterprises, such as Xiaomi, Huawei, NIO, and Minimax. Background Modern AI agents (e.g., Claude Code, Codex) frequently rely on third-party LLM intermediaries to invoke various models. These intermediaries function as application-layer proxies and can see all plaintext requests—including tool invocation parameters. Many developers directly embed keys and tokens into prompts or tool calls, allowing intermediaries to access vast amounts of sensitive information. In April 2026, Shou’s team published a paper titled “Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain” (arXiv:2604.08407). After testing 28 paid and 400 free intermediaries, they found: Some intermediaries actively inject malicious tool calls to steal credentials. One intermediary directly siphoned cryptocurrency from researchers’ test wallets (approximately $500,000). They could also “poison” intermediaries to reroute traffic through nodes under their control, briefly taking over approximately 400 hosts. This September post represents a continuation of that research: even “top-tier” Chinese intermediaries package and sell or leak user interaction data—particularly behavioral traces from high-capability Fable-level agents. Buyers can directly extract real production credentials from these datasets. What’s the core issue? The problem is not that hackers breached a specific company—it’s that the intermediate layer of the AI supply chain itself is fundamentally insecure: Intermediaries can see all plaintext traffic. Users and agents routinely send keys and tokens to intermediaries. This data is collected, stored, and sometimes sold as datasets. Once leaked, attackers no longer need to target individual companies—they can directly obtain the keys to internal systems. This represents a classic combined risk of “man-in-the-middle” and data leakage. For numerous Chinese enterprises heavily reliant on intermediaries to access cutting-edge models like Claude Fable and GPT, the impact is widespread.
ME NewsShare

Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.