Close Menu
CoinNewsJunction.comCoinNewsJunction.com
    What's Hot

    UK’s FCA warns football clubs over Crypto partnerships

    June 3, 2026

    5 Signs Users Missed in the AscendEX Collapse (Crypto Exchange Red Flags To Watch)

    August 4, 2026

    $60B Tokenized Potential in Philippines Seen as Opening Move, Not Limit

    December 1, 2025
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    Facebook X (Twitter) Instagram
    CoinNewsJunction.comCoinNewsJunction.com
    • News

      Axis Robotics Open-Sources One of the Largest Franka Arm Simulation Datasets for Physical AI

      September 4, 2026

      Chainlink deal to move $16 trillion with Bottomline lifts LINK

      September 3, 2026

      Fairshake enters US elections with $122M war chest

      September 2, 2026

      Rising Price Manipulation Attacks Increasingly Hurt Crypto Traders and Lenders

      September 1, 2026

      SEC Charges 38 Entities Over False Investment Adviser Filings

      August 31, 2026
    • Technology

      a16z says blockchain’s next test is fair execution, not raw speed

      September 4, 2026

      Sanders bill seeks permanent US ban on superintelligent AI

      September 3, 2026

      The NordVPN Dark Web Alert Everyone Mistook For a Hack

      September 2, 2026

      Ripple SettleMint Partnership Launches Tokenised Asset Platform

      September 1, 2026

      Kalshi bans George Santos for $17,839 market manipulation

      August 31, 2026
    • Learn/Guide

      OTC Crypto Prefunding: What 100% Upfront Actually Costs

      July 29, 2026

      Wadoozie ($WADZ): The Ethereum Memecoin With a 48-State Tour and Hidden Token Rewards

      May 7, 2026

      How to Optimize Company Operational Costs: A Manual on Modern Payment Ecosystems

      March 7, 2026

      6 Best Citizenship by Investment Programs for 2026

      February 24, 2026

      Best Smart Contract Auditors and Web3 Security Companies (2026): Ranked by Verifiable Public Evidence

      February 12, 2026
    • Regulation

      Polymarket Went Silent On $POLY, Here’s Everything That Happened Before That

      September 5, 2026

      ZachXBT Called Hardware Wallets “Garbage”, Trezor Just Proved He Was Being Too Generous

      September 4, 2026

      Tron Address Poisoning Attacker Sits On $9.4M After Draining 15 Wallets In A Month

      September 3, 2026

      LONG (long.xyz) Review: The Launchpad Turning Robinhood’s Stock Tokens Into a New Asset Class

      September 2, 2026

      5 Places To Search For New Crypto Tokens To Buy In 2026

      September 1, 2026
    • Live Pricing Chart
    CoinNewsJunction.comCoinNewsJunction.com
    Home»News»UC researchers warn third-Party AI routers are stealing crypto and private keys
    News

    UC researchers warn third-Party AI routers are stealing crypto and private keys

    April 13, 20263 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    UC researchers warn third-Party AI routers are stealing crypto and private keys - 1
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Third-party AI routing services are exposing users to significant security flaws that could result in the theft of cryptocurrency and cloud credentials.

    Summary

    • Researchers found that 26 third-party LLM routers are actively injecting malicious code and stealing credentials by exploiting their access to plaintext data.
    • The study revealed that intermediaries can intercept private keys and cloud credentials because they terminate secure encryption to aggregate AI requests.

    According to a paper published on Thursday by University of California researchers, the supply chain for Large Language Models (LLM) contains several vulnerabilities that allow for malicious code injection and credential extraction. 

    These intermediaries, which developers use to manage access to providers like Google or OpenAI, essentially act as a “middleman” that terminates secure encryption. 

    Because they have full plaintext access to every message sent through them, sensitive data like seed phrases or private keys can be intercepted by unverified infrastructure.

    The researchers tested 400 free and 28 paid routers to measure the extent of these risks. Nine of these services actively injected malicious code, while 17 separate routers were caught accessing Amazon Web Services credentials owned by the team. 

    During the experiment, one router successfully drained Ether from a decoy wallet after the researchers provided a prefunded private key. 

    Although the team kept the balances low to ensure the total loss remained under $50, the result confirmed how easily a compromised intermediary can siphon funds.

    “26 LLM routers are secretly injecting malicious tool calls and stealing creds,” co-author Chaofan Shou stated on X.

    Identifying a malicious router is a difficult task for the average user. The researchers noted that because these services must read data to forward it, there is no visible difference between legitimate handling and active theft. 

    The danger increases when developers enable “YOLO mode,” a setting in many AI frameworks that lets an agent execute commands automatically without a human confirming the action. 

    This allows an attacker to send instructions that the user’s system will run instantly, often without the operator’s knowledge.

    “The boundary between ‘credential handling’ and ‘credential theft’ is invisible to the client because routers already read secrets in plaintext as part of normal forwarding,” the study explained.

    Previously reliable routers can become dangerous if they reuse leaked credentials through weak relays. To prevent these attacks, the research team suggested that developers should never allow private keys or sensitive phrases to pass through an AI agent session. 

    A permanent solution would require AI companies to use cryptographic signatures. Such a system would allow an agent to mathematically prove that instructions came from the actual model rather than a tampered third-party source.

    “LLM API routers sit on a critical trust boundary that the ecosystem currently treats as transparent transport,” the paper concluded.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Axis Robotics Open-Sources One of the Largest Franka Arm Simulation Datasets for Physical AI

    September 4, 2026

    Chainlink deal to move $16 trillion with Bottomline lifts LINK

    September 3, 2026

    Fairshake enters US elections with $122M war chest

    September 2, 2026

    Rising Price Manipulation Attacks Increasingly Hurt Crypto Traders and Lenders

    September 1, 2026
    Top Posts

    Lummis says CLARITY Act can reshape U.S. crypto finance

    July 5, 2026

    Solana Price Eyes $100 as SOL Breakout Tests Key $78 Resistance

    August 12, 2026

    SBI Ripple Asia Partners With AWAJ to Drive XRPL Adoption Across Asia

    February 22, 2026

    Welcome to CoinNewsJunction.com! Your go-to source for fast, reliable updates from the ever-evolving world of cryptocurrency. Whether it's Bitcoin, altcoins, blockchain breakthroughs, or DeFi trends, we bring you timely insights, expert analysis, and key developments shaping the future of digital finance. Stay ahead with real-time crypto news and in-depth coverage.

    Top Insights

    Axis Robotics Open-Sources One of the Largest Franka Arm Simulation Datasets for Physical AI

    September 4, 2026

    Chainlink deal to move $16 trillion with Bottomline lifts LINK

    September 3, 2026

    Fairshake enters US elections with $122M war chest

    September 2, 2026
    Advertisement
    Demo
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    © 2026. Designed by CoinNewsJunction.com.

    Type above and press Enter to search. Press Esc to cancel.