律动BlockBeats
律动BlockBeats|Sep 11, 2026 04:02
[Purchase 6TB of Model Proxy Data to Obtain Keys? Researcher Claims to Have Access to Huawei, Xiaomi, and 19 Other Companies] Beating AI Newsflash: Security researcher Shou Chaofan revealed that he recently purchased approximately 6TB of Fable model invocation data from a leading Chinese model proxy platform. The data contained sensitive credentials such as SSH keys, VPN configurations, Alibaba Cloud keys, and GitLab tokens. He claimed that the keys in this dataset were sufficient to access the servers or internal systems of 19 leading Chinese enterprises, as well as 7 government-related institutions in China and the CIS region, including Huawei, Xiaomi, NIO, and MiniMax. Model proxy platforms act as intermediaries between users and models like Claude, with all requests and responses passing through them, allowing them to view plaintext in its entirety. If developers embed SSH keys, API keys, VPN configurations, and similar credentials into the agent context, and the proxy platform stores or even sells these records, the company's system keys could be leaked as well. This is not the first time Shou Chaofan has warned about the risks of proxy platforms. In an April paper, he and his team tested 428 LLM proxy platforms and found that 9 actively injected malicious code, 17 used AWS test keys intentionally planted by researchers to make actual AWS calls, and 1 directly transferred ETH from a test wallet. Shou Chaofan is the co-founder of blockchain security company Fuzzland and has long been engaged in vulnerability and supply chain security research. At the end of March, he was the first to discover that the Claude Code 2.1.88 release package inadvertently exposed approximately 500,000 lines of TypeScript source code through its source map. [Original Link]
+3
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads