TechLifestyler

Combining the best in Tech, Gaming, and Lifestyle to get through the day!

6TB Claude router leak hands out keys to Huawei, Xiaomi

Claude Mythos
A researcher pulled 6TB of leaked Claude router data and found live credentials tied to Huawei, Xiaomi, NIO and Chinese government systems.

Turns out the AI chatbot isn’t the weak link, the middleman routing your prompts to it is. A researcher going by Chaofan Shou dug through a 6TB data dump pulled from a China-based LLM router handling Claude traffic, and what he found reads like a hacker’s shopping list: SSH keys, VPN configs, cloud API tokens, GitLab credentials, the works.

Real Secrets, Real Targets

LLM routers sit between users and models like Claude, quietly logging prompts, tool calls and responses along the way. Developers and agents routinely paste sensitive credentials straight into those interactions, which means the logs end up holding the keys to the kingdom. In this case, that kingdom includes Huawei, Xiaomi, NIO, Minimax and a handful of Chinese and CIS government agencies. Six terabytes of raw, seemingly production traffic is not a small leak, it’s a live-fire security incident waiting to be exploited.

The timing is awkward too. Anthropic put out a threat intelligence report this week accusing labs like Moonshot and DeepSeek of quietly rerouting users to Claude and skimming reasoning traces through API gaps. Another researcher has since pushed back, arguing both labs return reasoning instantly enough that rerouting doesn’t add up, though a router pinching the traces and reselling them later is still very much on the table.

Either way, the actual villain here isn’t the model. It’s whoever’s guarding the pipe.


For more updates like this, head over to the news section!