26 LLM routers inject malicious tool calls and steal credentials, paper author alleges
The author alleges one router drained a client's $500,000 wallet and says their team also poisoned routers to redirect traffic to themselves.
TLDR
Third-party LLM routers dispatch AI agents' tool requests across providers. In an April 10, 2026 post sharing a paper, an author alleged that 26 routers were injecting malicious tool calls and stealing credentials, and that one drained a client's $500,000 wallet. The author also said their team had poisoned routers to forward traffic to them and could directly take over about 400 hosts within several hours.
Combined views
1
1 Source, first seen 20d ago