Esc
SafetyEmerging

Study finds malicious LLM routers hijacking agent tool calls

Is this a scandal?

Not yet — an early signal. Noise 36/100, holding steady, across 1 source.

SCAND-236544as of Methodology
Cite this incident"Study finds malicious LLM routers hijacking agent tool calls." SCAND.Ai incident SCAND-236544, noise 36/100 as of September 11, 2026. https://scand.ai/scandal/malicious-llm-routers-hijack-agent-tool-calls-study
FORECASTForecast, not fact

Enterprise adoption of AI agents will likely stall until standardized integrity verification protocols emerge because organizations cannot currently validate the safety of third-party API intermediaries.

36

Noise 36/100 — louder than 99% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

Third-party API intermediaries represent an unregulated attack surface that undermines trust in autonomous AI agents and exposes enterprise infrastructure to supply chain compromise.

Key points

  1. Researchers analyzed 428 LLM API routers and found active manipulation of model responses beyond simple logging.
  2. Nine routers were observed injecting malicious code directly into agent tool calls during execution.
  3. Seventeen incidents involved leaked AWS credentials or drained Ethereum wallets linked to router interference.
  4. Some malicious routers employed evasion tactics by waiting approximately 50 requests before initiating attacks.
  5. The attack vector relies on intermediaries terminating TLS connections to modify data within the trust chain.
  6. OpenRouter was explicitly cleared of wrongdoing, with malicious activity attributed to gray-market resellers.

The story

Security researchers identified multiple third-party LLM API routers actively modifying model responses to inject malicious code and exfiltrate credentials, according to a new study analyzing 428 services. The paper, titled "Your Agent Is Mine," reports that nine routers injected harmful payloads into tool calls, while seventeen cases involved exposed AWS credentials or drained cryptocurrency wallets. Crucially, some routers exhibited dormant behavior, functioning normally for dozens of requests before executing attacks to evade detection. The vulnerability stems from intermediaries terminating TLS connections, allowing them to alter data within the agent trust chain. The authors explicitly noted that OpenRouter was not among the malicious actors identified; compromised services were primarily free or gray-market resellers. This research highlights significant supply chain risks for developers using autonomous coding agents like Claude Code or Codex through unverified proxies.

Who's involved

Critic
arXiv Researchers

Published evidence showing third-party routers actively compromise agent security through response manipulation and credential theft.

Critic
Gray-Market Resellers

Unidentified low-cost API providers allegedly responsible for injecting malware and stealing credentials via TLS termination.

Defender
OpenRouter

Explicitly named in the study as a legitimate service not exhibiting the malicious behaviors found in gray-market alternatives.

How the conversation shifted

opinion has hardened

Polarity (0–100) from the noise pipeline, sampled over time.

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Murmur36?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 95%
Reach
38
Engagement
64
Star Power
20
Duration
16
Cross-Platform
20
Polarity
50
Industry Impact
50

The timeline

  1. Warning posted to r/LocalLLaMA

    User Thatisverytrue54321 summarizes findings and links to paper, highlighting delayed attack vectors.

  2. Research paper published on arXiv

    Study 'Your Agent Is Mine' documents analysis of 428 routers and identifies specific attack patterns.

The full record

The forecast

Enterprise adoption of AI agents will likely stall until standardized integrity verification protocols emerge because organizations cannot currently validate the safety of third-party API intermediaries.

Forecast, not fact — an editorial estimate we score when this resolves.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.

Follow this story

We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.

Tracking this story since September 11, 2026.