• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
  • HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Paper author accuses 26 LLM routers of injecting malicious tool calls and stealing credentials

    The author claims one router drained their client’s $500,000 wallet, and says their team also poisoned routers to redirect traffic to themselves.

    CS
    1 Source, 174d ago, first seen 174d ago

    TLDR

    In an April 10, 2026 post sharing a paper, an author alleged that 26 routers for large language models were injecting malicious tool calls and stealing credentials. They said one drained their client’s $500,000 wallet. The author also said their team had poisoned routers to forward traffic to themselves and claimed they could directly take over about 400 hosts within several hours.

    Combined views

    1.1M

    1 Source, first seen 174d ago

    Combined views

    1.1M

    1 Source, first seen 174d ago

    4.3K likes
    4.3K likes
    176 comments
    3.6K saves
    788 reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    176 comments
    3.6K saves
    788 reposts
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    1 Source

    @shoucccc26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet. We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts. Check our paper: https://arxiv.org/abs/2604.08407

    1 Source

    @shoucccc26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet. We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts. Check our paper: https://arxiv.org/abs/2604.08407