
Researcher Says 6TB of AI Relay Data Exposed Company Credentials

Researcher Says 6TB of AI Relay Data Exposed Company Credentials
WEEX View
- The main issue to watch is whether any named companies or agencies confirm exposure, rotate credentials, or dispute the researcher’s findings. The report describes access-enabling keys, but does not establish broader operational damage.
- The incident puts attention on AI relay stations as a market-structure weak point. These intermediaries can view full prompts and responses in plaintext, which raises risk when developers pass infrastructure credentials or internal configuration data through them.
- For crypto-adjacent infrastructure, the most important follow-up signal is whether service providers tighten logging, storage, and key-handling practices around AI tooling, especially where cloud access, code repositories, or wallet-related data may pass through third-party systems.
Security researcher Shou Chaofan said he purchased about 6TB of Fable model invocation data from a Chinese large-model relay station and found sensitive credentials that he said were sufficient to access servers or internal systems linked to 19 Chinese companies and seven government-related agencies.
According to Shou, the purchased dataset contained SSH keys, VPN configurations, Alibaba Cloud keys, and GitLab tokens. He said those credentials could provide access to the systems of entities including Huawei, Xiaomi, NIO, and MiniMax, as well as several government-related organizations in China and the CIS region.
The reported exposure centers on a large-model relay station, which acts as an intermediary that transmits requests and responses between users and AI models. Because that setup allows the relay station to see complete plaintext traffic, sensitive data included in prompts or context windows may be stored or resold by the intermediary, creating a path for credential leakage.
Shou said he had previously warned about the risks tied to relay stations. In a broader test of 428 LLM relay stations, he found that nine actively injected malicious code, 17 called AWS after seeing test keys, and one redirected ETH from a test wallet. The disclosure links AI application infrastructure risk with more familiar supply-chain and credential-management failures.
Shou is a co-founder of blockchain security firm Fuzzland and has focused on vulnerability and supply-chain security research. The available details do not include public responses from the named companies or agencies, nor do they specify how long the data had been retained, who operated the relay station, or whether the credentials were still active when reviewed.
Why It Matters
The case highlights an emerging security gap in AI infrastructure: intermediary services that sit between users and models may become high-value collection points for secrets far beyond model prompts. When developers place operational credentials inside AI workflows, a relay station can turn a convenience layer into a broad enterprise exposure point.
For crypto and AI-linked businesses, the significance goes beyond one alleged dataset sale. The same failure mode can affect cloud access, code repositories, and wallet-related operations, making AI tooling security a more immediate part of infrastructure risk rather than a separate application-layer concern.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreAmpleforth Proposal Raises Treasury Governance Attack Concerns
Ampleforth’s 54th governance proposal has been flagged as a suspected malicious attempt to transfer nearly all USDC held by a time-locked treasury contract, putting about 2.5 million USDC at risk.
Thailand SEC Seeks Feedback on Stablecoin Transfer Limits
Thailand’s SEC has opened a public consultation on proposed stablecoin rules that would bar third-party wallet transfers and cap daily deposits or withdrawals at 5 million baht per operator, pending final regulatory decisions.
Poolin Asset Auction Bid Climbs to $180 Million
Poolin creditors were told the bid for the bankrupt miner’s asset auction has risen to $180 million from a roughly $52 million baseline, though the sale still requires U.S. bankruptcy court approval and final creditor recoveries remain uncertain.
Hugging Face Seeks Access to Anthropic’s Evaluator Program
Hugging Face said it has launched an Open Alignment Initiative and applied to join Anthropic’s Embedded Evaluator program, a process that could give outside researchers on-site access to inspect model training and safety practices if approved.

