University of California research paper: AI agent routers have a critical vulnerability, stealing 26 secret encrypted credentials
A study by the University of California reveals security vulnerabilities in the supply chain of large language models (LLMs), especially malicious man-in-the-middle attacks that third-party routers may carry out. The research found that 26 routers injected malicious commands to steal credentials and sensitive data. Users have difficulty noticing the boundary between credential handling and theft, and the “YOLO mode” further increases security risk. The study recommends that developers isolate sensitive operations and choose router services with transparent auditing to strengthen protection.
ETH5,4%
MarketWhisper·04-13 03:03
