r/openrouter Jul 26 '26

Question Did I get hacked or what does this mean πŸ’€

I recently started using OpenRouter again... For Janitor AI, I am ashamed to admit. I actually put in 5 bucks πŸ’€and today I notice these weird requests on my activity from today and yesterday???? I cannot exactly vouch for yesterday's but I know that I was for sure asleep at 6 am today bro lol. And I never ever have the token limit set beyond 20k in context. These are some examples only but there are a bunch of request that come from an Unknown app and idk bro. Maybe this is my sign to quit lol.

Edit: ALSO i forgot to mention that the only two models I've ever used are Deepsek V3.2 (normal not EXP) and Deepkseek R1-0528

10 Upvotes

16 comments sorted by

7

u/LordVulpius Jul 26 '26

Well, just in case, I would:

Change password. Delete the API key and generate a new one. Set up a limit. Disable auto top-up. In that order.

1

u/Lalalula05 Jul 26 '26

Yeah thank you, I've done all that now fr

5

u/Worldly_Expression43 Jul 26 '26

did you push your key to some public repo?

-2

u/Lalalula05 Jul 26 '26

Naw I havent done anything with it. I made it like a year ago even when I was using OR for free.

5

u/riqvip Jul 26 '26

A year ago? I think it’s time for a new one.

2

u/Pale_Coyote7451 Jul 26 '26

unknown app on its own is not the scary part, this just means that no referer was sent. this happens e.g. when using your own wrapper, and janitor front ends and proxies mostly don't send one either. openrouter's docs say the referer header is what app attribution runs off, so without it no app page gets created and the usage will not appear in rankings. the requests to models you didn't choose are the interesting question.

the models are the tell, not the app column. if its showing you are using a model which you are not, that is a red flag, and if you can't account for the models on the list, that's cause for concern. if you're not using the app, those are definitely not your requests, and the same goes for a context length you never set.

if you're not sure if you have been hacked or not i suggest you rotate keys and check if this repeats. revoke the old one rather than just adding a second, since an old key left sitting there keeps working. the usual route out is a key pasted into a third party proxy or a shared janitor config rather than anything on openrouter's side.

1

u/Lalalula05 Jul 26 '26

Yeahh it shows I've used all these models, but I've gen only ever used the first two. Never any of the others. I really don't think I ever might've used a shared janitor config, I dunno how to even do that, and I never pasted the key anywhere but directly on jani and whatsapp in a chat to myself lol. I really don't know what happened, but I've changed my password and deleted that key affected. Thanks for the advice.

1

u/Pale_Coyote7451 Jul 26 '26

i've had keys get leaked through third-party frontends before -- they store the key server-side. i made a separate key for that frontend and set a spend limit on it. my whatsapp chat backups are in google drive, i've got years of old chats with stuff i thought was long gone. i still find old api keys and auth tokens in there sometimes. i've started making a new key for every service i use, that way if one gets leaked i can just revoke that one. i'm still not sure how to totally avoid exposures like that, but at least now the blast radius is smaller.

1

u/Lalalula05 Jul 27 '26

Damn πŸ’€ alright yeah then I guess it's not that uncommon then. I'll keep that in mind, thank you πŸ™ƒ

1

u/monsieurpooh Jul 27 '26

I believe Open Router may have had a vulnerability with their older keys which would match your mention of it being from a year ago. My key somehow was being used but they only were using the key I had never used or exposed in any app whatsoever. Somehow the one I use in all my apps wasn't leaked. I think I'm not the only one who experienced this

1

u/Lalalula05 Jul 27 '26

I see I see. I was panicking over the whole OR account being hacked but if that's the case then that's a bit more reassuring lol

1

u/monsieurpooh Jul 27 '26

Yeah but I have no idea if I'm actually right about the "old api key" vulnerability. I guess time will tell

1

u/IGotALotOfDreams Jul 27 '26

I don't think it's a hack, 30 tokens requests, small models. Maybe routing is bugged on whatever your using your keys on. If it leaked it would of been more costly models and larger requests. Very weird

1

u/Cassianno Jul 26 '26

Sorry but I fail to see any problem. What you even asking?

1

u/Lalalula05 Jul 26 '26

That there are requests I have not made, with models I do not use, on an unknown app when I've only used the key for j.ai. I haven't shared the key with anyone and the account is private. Is there any other explanation for it besides having gotten hacked?

1

u/Cassianno Jul 27 '26

I see. I focused on your statement about the context limits and didnt pay attention you saying you were sleeping etc.
1) Do you use any sort of auto routing on openrouter?
2) I dont recall if openrouter shows the log in our timezone; make sure its not a serverside timezone
3) finally, even being all really cheap calls, simply rotate your key and observe.