We spent months attacking the LLM API Router supply chain.... the thing sitting between your AI agent and OpenAI/Anthropic can read every prompt, steal every key, and rewrite every tool call.
Billions are at risk. Introducing our latest research: “Your Agent Is Mine” 🧵
@sheriyuo If you’re looking for tools to build self-evolving agents, we built something similar called AgentFlow. You might be interested in this:
https://t.co/QtYEZ7h2Mp
Chinese LLMs can hack better than state-sponsored hackers with properly evolved harness -
Kimi K2.5 managed to find and exploit 6 vulnerabilities in browsers: a single page view or an extension install by victims equal full system hijack.
Check https://t.co/d0SZSf1KqF
We audited popular ClawHub skills and found 50+ malicious / critically vulnerable ones that existing scanners missed.
Skills need program analysis. We translate natural language policies into Datalog, then deterministically check whether the skill can violate them.
Today, WorldClaw launches WorldRouter with @worldlibertyfi, one simple account to access 300+ AI models with competitive fees*.
No more jumping between ChatGPT, Claude and all the others. Same power, way cheaper.
This is your first step into the WorldClaw AgentOS.
👉 https://t.co/6x4XEjyUWc
#USD1 #WLFI #AI #AgentOS #WorldClaw #WorldRouter
*WorldRouter rates shown are priced approximately 30% below the corresponding model providers' published list rates at the time of publication. See website for more pricing details.
If you think vulnerability discovery is just about Mythos, think about the harness.
Today’s open-weight Chinese LLMs, with a properly evolved harness, can already outperform what people usually imagine only state-sponsored hackers can do.
Check our latest research ⬇️
Chinese LLMs can hack better than state-sponsored hackers with properly evolved harness -
Kimi K2.5 managed to find and exploit 6 vulnerabilities in browsers: a single page view or an extension install by victims equal full system hijack.
Check https://t.co/d0SZSf1KqF
🚨 ALERT: Researchers discover 26 third-party AI LLM routers secretly injecting malicious tool calls and stealing credentials.
Developers using AI coding agents like Claude Code to work on smart contracts or wallets may be at risk of having private keys and seed phrases compromised.
We spent months attacking the LLM API Router supply chain.... the thing sitting between your AI agent and OpenAI/Anthropic can read every prompt, steal every key, and rewrite every tool call.
Billions are at risk. Introducing our latest research: “Your Agent Is Mine” 🧵
5/ Shout out to my co-authors:
- Chaofan Shou @Fried_rice (open source enthusiast lol)
- Ryan Fang @ryanfang95 (co-founder of World Liberty Financial @worldlibertyfi)
- and my advisors and lab mates, Yu Feng (@captain8299), Hongbo Wen (@archidog0), Yanju Chen (@iffyanju)
Paper: https://t.co/6O9AsSB1aW
26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.
We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.
Check our paper: https://t.co/zyWz25CDpl
Let's talk about the FUD going around our WLFI Markets lending position.
It's wrong. Here's what's actually happening — and why the real story is a lot more interesting.