Cost: Official direct connections are usually pricier than proxy services, and topping up credits isn’t as easy. The upside is that many proxy services are cheap, and a single interface lets you access several different models.
In plain terms: A proxy service sits between you and the model provider, so it can see and alter both the prompts you send and the responses it returns. Researchers tested over 400 such services; nine slipped malicious code into replies, and seventeen tampered with cloud service keys that researchers had deliberately inserted. For setups where AI runs commands on its own, just one altered command can give an attacker full control of a computer.
Benefit: In June 2026, China’s Ministry of State Security issued a warning about these services. Some proxy providers keep user data on their servers, sometimes even selling it to other model makers for training purposes. Others hide backdoors that install harmful code on users’ devices, stealing account keys, cloud credentials, and even installing remote control tools. The advice is to stick to official direct connections or properly licensed platforms, avoiding any service of unknown origin lacking proper licensing and security safeguards. Always anonymize personal and project data before use, manage keys carefully, and rotate them regularly. If you notice unexpected charges, unexplained account bans, or odd data patterns, stop using the service, change all keys, run a virus scan, and keep records of what happened. In 2026, researchers from UC Santa Barbara and other institutions bought 28 paid proxy services from Taobao, Xianyu, and overseas shops, then gathered another 400 free ones from public forums. One paid and eight free services injected malicious code into tool calls — commands that let AI make your computer perform actions, such as installing software packages. Two services targeted only fully automated sessions; seventeen altered keys that researchers had placed there on purpose. One service even siphoned funds from a researcher’s Ethereum wallet, which held less than $50. The tampering was subtle: it swapped “requests” with the nearly identical “reqeusts” in installation commands, making it hard to spot at a glance. (National)
Evidence grade: B
Sources:国家安全部 (2026). 「AI中转站」,风险要防范. https://www.szzg.gov.cn/2026/xwzx/szkx/202606/t20260608_5331487.htm(数字中国建设峰会官网转载国家安全部微信公众号);Liu H, Shou C, Wen H, Chen Y, Fang RJ, Feng Y. (2026). Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain. arXiv:2604.08407. https://arxiv.org/abs/2604.08407
Notes: This item earned a B rating because only one study exists, and it’s a pre‑print — an unpublished draft. Most tested services were free; there were only 28 paid ones, so we can’t determine what percentage of all services are problematic. Some media misreported the theft amount as $500,000, while the paper cites under $50. The magnitude of benefit is rated as moderate: the potential losses from stolen keys and code vary widely, and no concrete figures appear in the research. If you’ve already used an untrusted proxy, revoke and regenerate all related keys at the model provider’s end, including those for cloud services and code repositories. When using such services, never let AI execute commands automatically; always review them first. Operators of these proxy services face criminal liability — see Section 11, Item 19 (AI proxy services). The main beneficiary is you, the user. 〔17〕 〔17〕
Never hand code, keys, or private data to dubious “AI proxy services,” especially when letting AI run commands automatically
Source material and reference translations have not been individually verified by this site. Health, safety and legal information does not replace advice specific to your circumstances.
Source and version
HowToLiveBetter — eternity4719 & contributors · CC BY 4.0
Reorganized here with reference translations; no endorsement by the original authors is implied.
a994b6a0c90598b0fe15cb837343f438dbf7b95d