MERCADOS:
BTC $81,317 ▲ +4.29%
ETH $2,529 ▲ +5.04%
SOL $184 ▲ +3.57%
IA STATUS Online RELOJ --:--:-- ART
📅 viernes, 11 de septiembre de 2026

TecnoSaberes

Inteligencia Artificial y Educación para Todos

🐉 LLMs de Oriente

Researcher Claims 6TB China LLM Router Logs Exposed Enterprise Credentials

Researcher Claims 6TB China LLM Router Logs Exposed Enterprise Credentials

Security researcher Chaofan Shou, co-founder of blockchain security firm Fuzzland, said he purchased roughly 6TB of model-invocation data from a Chinese large language model relay — also described as a router or proxy — and found sensitive credentials embedded in the logs. In posts and secondary reports circulating on September 11, including discussion around an X trend tied to the claim, Shou said the material included SSH keys, VPN configurations, Alibaba Cloud keys and GitLab tokens that he argued could be enough to reach servers or internal systems linked to about 19 Chinese companies and several government-related organizations. Named examples in those reports included Huawei, Xiaomi, NIO and MiniMax. Pandaily has not independently verified the dataset, key validity or any successful intrusion, and this article treats the episode as a reported research claim rather than a confirmed multi-enterprise breach. The technical framing is a familiar intermediary risk in the AI application supply chain. LLM routers sit between users and upstream models, often seeing full plaintext prompts and responses. When developers place infrastructure secrets inside agent contexts — keys, tokens, VPN profiles or repository credentials — a relay that stores or resells logs can turn a convenience layer into a credential collection point for enterprises and internet firms that rely on third-party routing. Shou has previously co-authored research on malicious intermediary attacks across hundreds of relays, reporting cases of injected tool calls, opportunistic use of planted cloud test keys and wallet diversion in controlled tests. Those earlier findings support the structural thesis even if the new 6TB purchase remains attribution by the researcher rather than a disclosure package from the named firms. Public details so far omit the operator identity of the relay, how long records were retained, and whether the credentials were still active when reviewed. No broad confirmations, forced rotations or official incident notices from the cited enterprises were available in the reporting surveyed for this piece. For vendors and users of China-facing LLM proxies, the practical takeaway is defensive and operational: treat relays as high-trust plaintext hops, keep secrets out of agent prompts, rotate any keys that may have traversed third-party routers, and prefer audited gateways with strict logging and retention controls. The story is a proxy-router security warning about credential hygiene in agent workflows, not a verified catalog of compromised networks or a geopolitical narrative.

Fuente: Pandaily (China AI)

AL

Sobre Andrés LLM

Especialista en Modelos Asiáticos (DeepSeek, Kimi, Qwen, GLM)

Periodista y analista en Tecno Saberes especializado en la cobertura de Inteligencia Artificial y Educación para Todos.

🚀 Potenciá tu criterio digital y habilidades en IA

Tecno Saberes es una iniciativa de divulgación tecnológica asistida por Inteligencia Artificial y orquestada por el equipo de TucMara.com.