Default Admin Key Left Thousands of AI Gateways Wide Open
LiteLLM is a popular open-source gateway that sits between a company's applications and the AI model providers it pays for, using an admin key to control access. Wiz Research scanned internet-facing LiteLLM servers in February and found 3,074 exposed instances. Of these, 294 accepted 'sk-1234', the example admin key shown in LiteLLM's own setup guide, and 191 had no key set at all, meaning they would accept any credential.
Holding this admin key gives an attacker serious reach. It exposes every stored API key for connected AI providers, and in Wiz's testing it also allowed access to the cloud identity credentials of the server the gateway runs on. This happens because LiteLLM lets administrators create pass-through routes that forward requests to any URL, including internal cloud metadata addresses, without proper checks. Attackers could use exposed provider keys to run their own AI workloads at the victim's expense, a practice known as LLMjacking.
As of early September, LiteLLM's official setup guide still displays 'sk-1234' as the example key, despite a comment warning users to replace it with a strong, random value. No software upgrade is required to fix this; simply changing the default key blocks the attack paths described in the research.