Return to Threats

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

thehackernews.com 2026-09-10 AI supply chain Critical

What Happened

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every

Why It Matters

Report facts: Wiz Research found that nearly one in ten internet-facing LiteLLM gateways accepted 'sk-1234', the example admin key from LiteLLM’s setup guide, meaning these instances were effectively left with a default administrator credential and exposed to anyone who tried it. This misconfiguration affects an open-source AI gateway that intermediates between applications and paid model providers, so compromise of the admin key could allow attackers to inspect or modify traffic and configurations. RealGround analysis: This is primarily an AI supply chain and configuration hygiene issue, where insecure defaults in an AI middleware component create systemic exposure across multiple downstream applications and models. Organizations using AI gateways should implement strict credential management, harden default configurations, and continuously inventory and assess AI infrastructure components for exposed admin interfaces and weak or example keys.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

Talk to AI CISO