According to ChainCatcher, security researcher Shou Chaofan said he had just bought about 6 TB of Fable model invocation data from a leading Chinese large-model gateway service. The data, he said, contained sensitive credentials including SSH keys, VPN configurations, Alibaba Cloud keys and GitLab tokens.
Shou said the keys in that dataset were sufficient to access servers or internal systems at 19 major Chinese companies, as well as seven government-related entities in China and the Commonwealth of Independent States. The organizations he named included Huawei, Xiaomi, NIO and MiniMax.
The report said such large-model gateways sit between users and models including Claude, with both requests and responses passing through the gateway first. That gives the operator visibility into the full plaintext. If developers place SSH keys, API keys or VPN configurations into an agent context, and the gateway stores or sells those records, corporate system credentials can be exposed as well.
ChainCatcher said this was not the first time Shou had warned about the risks tied to model gateways. In a paper released in April that he took part in, researchers tested 428 LLM gateways. They found that nine would actively inject malicious code, 17 used AWS test keys after researchers intentionally planted them, and one directly transferred ETH out of a test wallet.
Shou is the co-founder of blockchain security firm Fuzzland and has long focused on vulnerability and supply-chain security research. At the end of March, he also said he was the first to discover that a source map in the Claude Code 2.1.88 release package had accidentally exposed about 500,000 lines of TypeScript source code.

