The Weakest Link: How “Transit Hubs” are Quietly Draining Crypto and Stealing AI Data
ID: f67e1702-1bb1-5919-9976-facf87b1e307
STIX ID: report--f67e1702-1bb1-5919-9976-facf87b1e307
Feed Name: securityonline.info
**Executive summary:** A security research audit of 28 premium and 400 free API aggregators found that because TLS provides only hop-by-hop encryption, intermediary routing nodes can read and manipulate plaintext JSON payloads (prompts, API keys, tool parameters, responses). The team documented multiple active abuses — malicious code injection by nine hubs, adaptive evasion triggers, capture of canary AWS credentials, instantaneous theft and consumption of API keys (≈100M tokens and 2.1B tokens across decoys), exposure of 99 credentials, and direct theft of Ethereum from a honeypot — and recommends provider-signed response envelopes, stricter sandboxing and policy controls, and reputation-based hub vetting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
