Researcher says 6TB of model relay data exposed credentials tied to major Chinese firms

Researcher says 6TB of model relay data exposed credentials tied to major Chinese firms

N
News Editor
2026-09-11 03:59:41
Security researcher Shou Chaofan said he purchased about 6TB of Fable model call data from a leading Chinese large-model relay service and found sensitive credentials in the dataset, including SSH keys, VPN configurations, Alibaba Cloud keys and GitLab tokens. He said the keys were sufficient to access servers or internal systems at 19 major Chinese companies and seven government-related institutions in China and the Commonwealth of Independent States, naming Huawei, Xiaomi, Nio and MiniMax among the affected organizations. According to Shou, relay platforms sit between users and models such as Claude, meaning both prompts and responses pass through them in plaintext. If developers place SSH keys, API keys or VPN configurations into an agent context, and the relay stores or sells those records, company credentials can leak with the traffic. Shou said this is not his first warning on the issue. A paper he worked on in April tested 428 LLM relay services and found that nine actively injected malicious code, 17 used planted AWS test credentials to make real AWS calls, and one transferred ETH out of a test wallet. Shou is a co-founder of blockchain security firm Fuzzland and has long focused on vulnerability and supply-chain security research.

Security researcher Shou Chaofan said he recently bought about 6TB of Fable model call data from a leading Chinese large-model relay service. The dataset contained sensitive credentials, including SSH keys, VPN configurations, Alibaba Cloud keys and GitLab tokens.

He said the keys in that data were enough to let him access servers or internal systems at 19 major Chinese companies and seven government-related institutions in China and the Commonwealth of Independent States. He named Huawei, Xiaomi, Nio and MiniMax among them.

Shou said large-model relay services sit between users and models such as Claude, so both requests and responses pass through the relay first. That gives the operator visibility into the full plaintext. If developers place SSH keys, API keys or VPN configurations into an agent context, and the relay stores or even sells those records, company system credentials can leak along with them.

Shou said this was not his first warning about relay-service risk. In an April paper he worked on, researchers tested 428 LLM relay services. They found that nine actively injected malicious code, 17 used AWS test credentials that had been deliberately planted by the researchers to make actual AWS calls, and one directly moved ETH out of a test wallet.

Shou is a co-founder of blockchain security company Fuzzland and has long focused on vulnerability and supply-chain security research. In late March, he also said he was the first to discover that the source map in the Claude Code 2.1.88 release package had unintentionally exposed about 500,000 lines of TypeScript source code.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.