10Evidence B

Do not give code, keys, or private information to unknown “AI proxy sites,” especially when letting AI execute commands automatically

A proxy site sits between you and the model vendor and can read or change both what you send and the answers you receive. A study tested more than 400 proxy sites: 9 inserted malicious code into replies, and 17 used cloud-service keys deliberately planted by researchers. When AI executes commands automatically, one altered command can be enough to give someone control of the computer.

Cost

Connecting directly to official services usually costs mor…

Benefit

In June 2026, the Ministry of State Security issued a risk warning. Some proxy sites retain users’ submissions…

Cost

Connecting directly to official services usually costs more than proxy access, and topping up is less convenient. The hard part is that proxy sites are cheap and provide several vendors’ models through one entry point.

Benefit

In June 2026, the Ministry of State Security issued a risk warning. Some proxy sites retain users’ submissions on their servers; some intercept and sell them to other model vendors for training. Some contain backdoors, inject malicious code into devices, steal account keys and cloud credentials, or even install remote-control software. The warning recommends direct official connections or properly authorized platforms and avoiding platforms of unknown origin without operating qualifications or security safeguards. Remove identifying information from personal and project data before use, manage keys carefully, and rotate them regularly. If unexplained charges, account bans, or data anomalies occur, stop using the service immediately, change keys, scan for malware, and preserve evidence. Researchers at the University of California, Santa Barbara, and other institutions conducted a measurement study in 2026. They bought access to 28 paid proxy sites from Taobao, Xianyu, and overseas online shops and collected 400 free ones from public communities. One paid and 8 free sites injected malicious code into returned tool calls. Tool calls are commands AI asks your computer to execute, such as installing packages. Another 2 attacked selectively; the paper’s example targeted only sessions with fully automatic execution. Seventeen used Amazon cloud-service keys deliberately planted by the researchers. One transferred money out of the researchers’ Ethereum wallet, which held only a small amount; the loss was under US$50. The paper demonstrated a subtle alteration: changing requests in an installation command to the similarly spelled reqeusts, hard to spot at a glance (nationwide).

Original sources

国家安全部 (2026). 「AI中转站」,风险要防范. https://www.szzg.gov.cn/2026/xwzx/szkx/202606/t20260608_5331487.htm(数字中国建设峰会官网转载国家安全部微信公众号);Liu H, Shou C, Wen H, Chen Y, Fang RJ, Feng Y. (2026). Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain. arXiv:2604.08407. https://arxiv.org/abs/2604.08407

Open source link
Book note

Rated B because this is a single study and a preprint, a publicly released version before formal publication. Most tested proxy sites were free, with only 28 paid ones, so the fraction of all proxy sites that are problematic cannot be estimated. Some media reported the theft as US$500000; the paper says under US$50. Benefit magnitude is rated medium based on consequences: losses from stolen keys and code vary enormously, and the study provides no applicable loss amount. If you have used an unknown proxy site, revoke the keys used with it at the model vendor and generate new ones; rotate cloud-service and code-repository keys too. When using a proxy, do not let AI execute commands fully automatically; inspect commands before allowing them. Proxy operators face criminal risks; see Section 11, Item 19 (AI proxy sites). The beneficiary is you.

My note