6TB of Sensitive Data on Black Markets: When Your AI Assistant Becomes a Hacker’s “Inside Man”
Recently, a massive 6TB dataset of LLM API calls hit the black market, containing unmasked enterprise credentials capable of compromising internal systems at Huawei, Xiaomi, NIO, and more. This incident exposes a hidden security black hole behind Large Language Model (LLM) proxies.
The "Shadow IT" Trap Behind Cheap Compute
In the rush to adopt AI development efficiency, an overlooked gray area has become a "black hole" for corporate data security. A recent test by security researcher Chaofan Shou exposed the shocking vulnerabilities behind LLM Proxies/Router services.
For just five figures in USD, he purchased a massive 6TB dataset of Fable model API calls from a top-tier domestic proxy provider. This wasn't just logs; it was a treasure trove of "internal network keys." It contained大量 unmasked critical credentials, including GitLab tokens, SSH private keys, VPN configs, and root-level cloud access keys.
Using these credentials, attackers could take over internal systems at 19 top tech companies (including Huawei, Xiaomi, NIO, MiniMax) and 7 national research institutions (like Zhangjiang Lab and USTC).
How AI Assistants Become "Thieves"
LLM proxies emerged because developers seek cheaper, stable API access to services like OpenAI or Anthropic, bypassing regional/payment restrictions. This is essentially "Shadow IT"—sacrificing security audits for convenience and cost.
However, any application-layer proxy without end-to-end encryption is essentially a traffic sniffer. When developers point AI coding assistants (like Claude Code, Cursor) to these unaudited proxies, danger lurks:
- Auto-reading Sensitive Files: AI assistants automatically read project files and environment variables (.env), which often contain SSH keys and cloud secrets.
- Plaintext Transmission Risk: These details travel with the request context to the proxy. Since the proxy must decrypt and rewrite requests to forward them, it captures everything in plaintext.
- Data Commodification: Some proxies sell these data packets containing sensitive info directly on black markets.
From "Passive Leak" to "Active Malice"
If data leakage is passive risk, the "active malice" of proxies is far more destructive. The research team highlighted this in their paper, Your Agent Is Mine.
The study stemmed from a real case: a client used a third-party proxy, had their private key intercepted, and saw ,000 worth of crypto assets drained in minutes.
The team tested 428 LLM API routers with alarming results:
| Attack Type | Findings |
|---|---|
| Automated "Credential Fishing" | 17 proxies automatically extracted cloud credentials and attempted unauthorized probes. |
| Overt Theft | One proxy detected a test wallet private key and instantly transferred the ETH. |
| Paid Services Also "Poisoned" | 9 out of 28 paid proxies actively tampered with model responses, injecting malicious code or backdoors. |
Conclusion: Efficiency Shouldn’t Cost Security
The proliferation of LLM proxies is an extreme evolution of "Shadow IT" in the AI era. It highlights corporate negligence regarding supply chain security and over-privileged access.
As AI coding assistants bind deeply with production environments, any decision to hand over communication control for the sake of lower compute costs can escalate into a major security breach. Building a secure AI supply chain is no longer optional—it’s essential.
Celedog.io: Committed to Secure & Auditable Access
To counter these industry risks, Celedog.io ensures that all model接入 (access) comes from auditable and securely penetrable compliant channels. This includes but is not limited to AWS/Aliyun, multi-national carriers, original model manufacturers, and Celedog’s own AIDC.
Celedog.io strictly adheres to the "Three No's Principle":
- No Data Retention: We do not store user data.
- No Model Training: We do not use user data to train models.
- No Non-Compliant Partnerships: We do not cooperate with non-compliant channels.
Source: Original Article (163.com)
Last updated September 11, 2026
Where to go next
- Try Celedog — free credits on signup, no card required.
- API documentation
- Per-model pricing
- More Celedog Blog