BTC $77,069.41 -1.54%
ETH $2,458.27 -0.63%
BNB $716.06 -0.73%
XRP $1.35 -2.94%
SOL $99.64 -2.17%
TRX $0.3389 -0.21%
DOGE $0.0840 -1.86%
ADA $0.2100 -1.33%
BCH $227.93 -8.79%
LINK $11.53 -2.38%
HYPE $79.51 -5.29%
AAVE $122.87 -1.68%
SUI $0.7393 -3.65%
XLM $0.1760 -2.26%
ZEC $1,086.47 -12.50%
BTC $77,069.41 -1.54%
ETH $2,458.27 -0.63%
BNB $716.06 -0.73%
XRP $1.35 -2.94%
SOL $99.64 -2.17%
TRX $0.3389 -0.21%
DOGE $0.0840 -1.86%
ADA $0.2100 -1.33%
BCH $227.93 -8.79%
LINK $11.53 -2.38%
HYPE $79.51 -5.29%
AAVE $122.87 -1.68%
SUI $0.7393 -3.65%
XLM $0.1760 -2.26%
ZEC $1,086.47 -12.50%

Researchers claim that purchasing 6TB of relay station data can breach 19 companies including Huawei and Xiaomi

2026-09-11 12:18:35

Security researcher Shou Chaofan stated that he just purchased about 6TB of Fable model invocation data from a leading Chinese model relay station, which included sensitive credentials such as SSH keys, VPN configurations, Alibaba Cloud keys, and GitLab tokens. He claimed that the keys in this batch of data were sufficient for him to access the servers or internal systems of 19 leading Chinese companies, as well as 7 Chinese and CIS government-related agencies, including Huawei, Xiaomi, NIO, and MiniMax.

The model relay station is positioned between users and models like Claude, so requests and responses pass through it first, allowing it to see the complete plaintext. Once developers insert SSH Keys, API Keys, VPN configurations, etc., into the Agent context, if the relay station saves or even sells these records, the company's system keys will also leak out. This is not the first time Shou Chaofan has warned about the risks of relay stations. A paper he participated in tested 428 LLM relay stations in April and found that 9 actively injected malicious code, 17 actually used AWS test keys deliberately placed by researchers to call AWS, and 1 directly transferred ETH from the test wallet.

Shou Chaofan is a co-founder of the blockchain security company Fuzzland and has long been engaged in vulnerability and supply chain security research. At the end of March, he also first discovered that the source map in the Claude Code 2.1.88 release package accidentally exposed about 500,000 lines of TypeScript source code.

app_icon
ChainCatcher Building the Web3 world with innovations.