Study finds malicious LLM routers hijacking agent tool calls
Is this a scandal?
Not yet — an early signal. Noise 36/100, holding steady, across 1 source.
Enterprise adoption of AI agents will likely stall until standardized integrity verification protocols emerge because organizations cannot currently validate the safety of third-party API intermediaries.
Noise 36/100 — louder than 99% of tracked AI controversies.
Why it matters
Third-party API intermediaries represent an unregulated attack surface that undermines trust in autonomous AI agents and exposes enterprise infrastructure to supply chain compromise.
Key points
- Researchers analyzed 428 LLM API routers and found active manipulation of model responses beyond simple logging.
- Nine routers were observed injecting malicious code directly into agent tool calls during execution.
- Seventeen incidents involved leaked AWS credentials or drained Ethereum wallets linked to router interference.
- Some malicious routers employed evasion tactics by waiting approximately 50 requests before initiating attacks.
- The attack vector relies on intermediaries terminating TLS connections to modify data within the trust chain.
- OpenRouter was explicitly cleared of wrongdoing, with malicious activity attributed to gray-market resellers.
The story
Security researchers identified multiple third-party LLM API routers actively modifying model responses to inject malicious code and exfiltrate credentials, according to a new study analyzing 428 services. The paper, titled "Your Agent Is Mine," reports that nine routers injected harmful payloads into tool calls, while seventeen cases involved exposed AWS credentials or drained cryptocurrency wallets. Crucially, some routers exhibited dormant behavior, functioning normally for dozens of requests before executing attacks to evade detection. The vulnerability stems from intermediaries terminating TLS connections, allowing them to alter data within the agent trust chain. The authors explicitly noted that OpenRouter was not among the malicious actors identified; compromised services were primarily free or gray-market resellers. This research highlights significant supply chain risks for developers using autonomous coding agents like Claude Code or Codex through unverified proxies.
Who's involved
Published evidence showing third-party routers actively compromise agent security through response manipulation and credential theft.
Unidentified low-cost API providers allegedly responsible for injecting malware and stealing credentials via TLS termination.
Explicitly named in the study as a legitimate service not exhibiting the malicious behaviors found in gray-market alternatives.
How the conversation shifted
Polarity (0–100) from the noise pipeline, sampled over time.
Noise Level
The timeline
Warning posted to r/LocalLLaMA
User Thatisverytrue54321 summarizes findings and links to paper, highlighting delayed attack vectors.
Research paper published on arXiv
Study 'Your Agent Is Mine' documents analysis of 428 routers and identifies specific attack patterns.
The full record
Sources & methodology
Every claim above traces to these primary items. How we score →
The forecast
Enterprise adoption of AI agents will likely stall until standardized integrity verification protocols emerge because organizations cannot currently validate the safety of third-party API intermediaries.
Forecast, not fact — an editorial estimate we score when this resolves.
That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.
Follow this story
We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.
Tracking this story since September 11, 2026.
Join the Discussion
Discuss this story
Community comments coming in a future update
Be the first to share your perspective. Subscribe to comment.