Nearly one in ten exposed LiteLLM AI gateways still accept the example admin key
Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.
- Check
- Change the LiteLLM admin key immediately if it is still the default sk-1234, which needs no upgrade, and upgrade LiteLLM to 1.84.0 or later to close the exploited code-execution and auth-bypass flaws.
- Affected
- Organizations running internet-facing LiteLLM gateways, especially with the default admin key or on unpatched versions; an attacker can read every stored provider API key, reach cloud credentials, and sometimes execute code.
- Fix
- Replace default keys, patch to the latest LiteLLM, take gateways off the public internet, rotate all provider, cloud, and database credentials it can reach, and treat AI gateways as tier-zero secrets stores.