Researchers Find 26 LLM Routers Secretly Injecting Malicious Instructions, With $500,000 in Crypto Stolen
LLM routers act as API intermediaries between AI agents such as Claude Code and model providers including OpenAI and Anthropic. They can decrypt, read and modify entire requests and tool calls. As agents increasingly write code, manage cloud infrastructure and operate wallets, a compromised router — a trusted node lacking signed responses — could expose private keys and credentials without users noticing.
Teams from UC Santa Barbara, UC San Diego and Fuzzland submitted the research on April 9, 2026. Tests of 428 routers found that nine injected malicious code, 17 accessed decoy AWS credentials and one transferred less than $50 worth of ETH from a test wallet. Chaofan Shou separately said a client's wallet containing $500,000 had been drained.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →