LLM Heist: hijacking a LiteLLM gateway for traffic interception, key theft and forged tool-calls
Research demonstration03 Aug 2026A control-plane and gateway-abuse class distinct from the LiteLLM PyPI-backdoor and MCP-test-endpoint RCE cases already tracked: it forges tool invocations at the forwarding layer (post-inference response injection), a channel prompt-injection guardrails cannot observe because manipulation happens after the model produces output.
Risks it illustrates
Sources
Practise the risk class — related scenarios
Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).
An 'Ask AI' button quietly plants a permanent 'trusted source' rule in your assistant's memory
An ops agent gets one god-mode credential — and one misread wipes production
A coding agent asks to write ./notes.txt — the file it actually overwrites is your SSH keys
A support email hides instructions — and the assistant obeys them
A text-to-SQL agent runs the model's output straight at the database
A speed optimisation becomes a cross-tenant listening device
Compromise the pipeline that builds agents, and every new worker is born malicious
Two doors to the same secret: reconstruct the model through its API, or just walk off with the weight file
A fake Sentry error report hijacks a developer's coding agent into running a shell command
Every command is harmless on its own — the sequence is the exploit
The forensic record is itself the attack surface — an agent's log is poisoned, then quietly rewritten
One click provisions an attacker-configured agent inside your own workspace
An attacker plants prompt injection in the audit trail — so the LLM that hunts them erases the evidence
Encoded public text is laundered across an agent handoff into an on-chain transfer
A cost-saving open-weights swap quietly ships a model with its safety surgically removed
A screenshot that's harmless at full size becomes an order once the system shrinks it
A capable third-party model that behaves perfectly — until it sees the trigger
An attacker captures the agent's bearer token — and inherits its authority
A trusted MCP email tool quietly BCCs every message to an attacker
A forged peer registers on the agent directory — and the planner enlists it
A poisoned web page hijacks a research agent — and the planner acts on its behalf
A GUI agent clicks 'Continue' — but the screen moved, and it lands on 'Send'
An inbox summary quietly ships a secret to an attacker's server