Security researcher Chaofan Shou published research showing that 26 third-party LLM routers — services that sit between AI agents and model providers like OpenAI or Anthropic — were secretly injecting malicious tool calls and harvesting credentials from the plaintext traffic passing through them. Malicious code injection was found in 9 routers and credential harvesting in 17, and one router’s behavior was directly tied to a customer’s crypto wallet being emptied of $500,000. Researchers also demonstrated a poisoning attack that redirected traffic from roughly 400 hosts through an attacker-controlled router within hours.