연구자가 중국 기반 LLM 라우터로부터 6TB Anthropic Claude 훈련 데이터 덤프를 구매; Xiaomi, Huawei, 중국 정부 기관과 연결된 민감한 보안 취약점 데이터 발견
AI model routers are emerging as one of the most significant threat vectors for data security. This vulnerability was starkly illustrated when a researcher obtained a 6TB dataset from a China-based LLM router and uncovered sensitive credentials that could compromise multiple government entities and major Chinese companies.
LLM routers function as intermediaries that forward requests from users and agents to various language models, including high-end options like Anthropic's Claude Fable. These routers typically log prompts, tool calls, responses, and associated metadata. Because AI agents and developers frequently embed sensitive information—SSH keys, VPN configurations, cloud API keys, GitLab tokens, and similar credentials—directly into their interactions with these systems, the logged data can contain usable secrets.
Researcher Chaofan Shou discovered a substantial cache of credentials within the 6TB data dump from a Chinese router connected to Anthropic's Claude. The cache contained enough secrets to potentially compromise systems belonging to multiple Chinese and CIS government entities, as well as major firms including Xiaomi, Huawei, NIO, and Minimax.
The scale of the dataset and the presence of live credentials within Claude-related routing sessions indicate raw or near-raw production traffic dumps rather than curated training data. This aligns with earlier research on malicious intermediary attacks against LLM routers, demonstrating how compromised or poorly secured routers can leak or be used to exfiltrate secrets at scale.
Anthropic recently published a report alleging that Chinese AI labs such as Moonshot and DeepSeek had redirected users to its Claude models and recovered reasoning traces through vulnerabilities in the Anthropic API. However, this claim has been contested by researchers who argue that Moonshot and DeepSeek offer instantaneous, real-time reasoning traces to users, making it virtually impossible for them to have rerouted queries to Anthropic's Claude. It remains possible that LLM routers independently recovered Claude's reasoning traces and subsequently sold them to these AI labs.