Chain Reaction After Credential Theft Case: AI Gateway Giant LiteLLM Cuts Ties with Delve, Mired in Compliance Fraud Scandal

marsbit发布于2026-03-31更新于2026-03-31

文章摘要

A major security and compliance crisis has unfolded in the AI infrastructure sector. Popular AI gateway developer LiteLLM has officially announced the termination of all cooperation with compliance startup Delve and plans to redo its security certification through a competitor, Vanta. The rupture was triggered by a recent severe credential-stealing malware attack on LiteLLM's open-source version. Prior to the attack, LiteLLM had relied on Delve's services to obtain two key security certifications. However, Delve is now facing serious integrity allegations, accused of misleading clients by fabricating data and employing auditors who provided rushed certifications, creating a false sense of compliance. Despite public denials from Delve's founder, the release of evidence by an anonymous whistleblower has intensified scrutiny. In response, LiteLLM's CTO, Ishaan Jaffer, outlined the company's stance: immediately cutting ties with Delve, recommencing certification with Vanta, and engaging an independent third-party auditor for a thorough review of its compliance controls. As a leading AI gateway with millions of developers, LiteLLM's decisive action highlights the industry's heightened sensitivity to authentic compliance. In the wake of the attack, companies are shifting focus from mere paper-based compliance to seeking genuine technical security verification.

The "security and compliance crisis" that has sent shockwaves through the artificial intelligence infrastructure sector saw the latest developments today. Popular global AI gateway developer LiteLLM officially announced the termination of all cooperation with compliance startup Delve , and plans to re-undergo security certification through a competitor.

Core Event Recap

The trigger for this split was the severe credential-stealing malware attack suffered by the LiteLLM open-source version last week. Prior to the attack, LiteLLM had relied on Delve's compliance services to obtain two key security certifications. However, Delve has recently been embroiled in a serious integrity crisis, accused of misleading clients into a false sense of compliance with weak security protections by fabricating data and hiring auditors who provided "cursory sign-offs".

Positions and Developments

Although the founder of Delve publicly **denied the allegations** and promised to provide free re-inspections, evidence subsequently released by an anonymous whistleblower further fueled public discourse.

Faced with this dual blow to security and trust, LiteLLM's Chief Technology Officer Ishaan Jaffer clarified the company's stance today via a social platform:

  • Immediate Severance: Completely halt all cooperation with Delve.

  • Re-certification: Commission Delve's main competitor, Vanta , to restart the certification process.

  • Enhanced Auditing: Hire an independent third-party auditing firm to conduct in-depth validation of compliance controls.

Industry Impact

As a benchmark AI gateway with millions of developers, LiteLLM's "drastic move to save itself" reflects the AI industry's high sensitivity to the authenticity of compliance. Under the shadow of the credential theft attack, companies are shifting from merely pursuing "paper compliance" to seeking genuine technical security verification.

热门币种推荐

相关问答

QWhat was the main reason for LiteLLM terminating its partnership with Delve?

ALiteLLM terminated its partnership with Delve due to a severe security compliance crisis, where Delve was accused of misleading clients by fabricating data and employing auditors who provided hasty, unreliable certifications, which left LiteLLM vulnerable to a credential-stealing malware incident.

QWhat specific actions did LiteLLM's CTO announce in response to the security incident and compliance issues?

ALiteLLM's CTO, Ishaan Jaffer, announced three key actions: immediately cutting all ties with Delve, recommencing the certification process with Delve's competitor Vanta, and engaging an independent third-party auditor to conduct a deep validation of compliance controls.

QWhat industry shift does the LiteLLM incident reflect regarding compliance and security?

AThe incident reflects a shift in the AI industry from pursuing mere 'paper compliance' to seeking genuine technical security verification, emphasizing real safety over certifications that may not reflect actual security posture.

QHow did Delve respond to the allegations of compliance fraud?

ADelve's founder publicly denied the allegations and offered free re-inspections to clients, but anonymous whistleblowers later released evidence that further fueled the controversy.

QWhat was the initial event that triggered the scrutiny of Delve's compliance certifications for LiteLLM?

AThe initial trigger was a severe credential-stealing malware attack on LiteLLM's open-source version, which occurred after LiteLLM had obtained security certifications through Delve, raising questions about the effectiveness and legitimacy of those certifications.

你可能也喜欢

比特币提现仍在继续:Coldcard冷钱包8年存储终成空

硬件钱包Coldcard遭黑客攻击,导致大量资金从易受攻击设备中被持续转出。据Galaxy Research数据,截至2026年8月2日,已有4585个地址被盗,损失总额达1367.05 BTC(约合8860万美元),远超7月30日最初报告的594.5 BTC。大部分被盗资金仍停留在攻击者地址。 问题根源并非固件,而是设备生成的种子短语存在漏洞。2021年3月起,因程序员错误集成libNgU库,设备从使用STM32硬件随机数生成器转为使用软件生成器Yasmarang,该生成器由公开可获取的芯片序列号和计时器状态初始化,导致生成的种子短语可在离线状态下被暴力破解。即使固件后续已更新,只要用户未将资金转移至基于新种子短语生成的新地址,旧钱包就始终处于风险中。 受影响的设备包括特定固件版本的Mk2/Mk3、Mk4/Mk5及Q系列。仅当种子短语是通过至少50次独立掷骰子或强唯一性BIP-39密码短语创建时方可幸免。官方建议受影响用户立即在已修复的固件上生成新种子短语并转移资产。 报道提及一位39岁投资者的案例,他因该漏洞损失了2 BTC(约13万美元)。他多年来通过体力劳动积攒比特币,将其视为在制裁和高通胀国家中的财务保障与提前退休的途径。此次事件使他的长期持有策略和“冷存储”信心遭受重击,他因此决定彻底退出加密货币领域。 从历史数据看,随机数生成器缺陷并非首例,类似问题曾导致巨额损失。此次事件警示,即使离线存储也未必绝对安全,其安全性高度依赖于底层硬件和算法的可靠性。

cryptonews.ru1小时前

比特币提现仍在继续:Coldcard冷钱包8年存储终成空

cryptonews.ru1小时前

帕克·刘易斯解释为何比特币仍是最佳货币

知名比特币分析师帕克·刘易斯在访谈中批评了某些上市公司以“数字信贷”形式销售永续优先股的营销策略,认为这从根本上扭曲了比特币的本质。他指出,比特币在算法层面不具备法币收益性,承诺定期分红主要依赖牛市吸引新投资者来维持,风险极高。 刘易斯引用数据说明此类衍生品的巨大风险:全球信贷市场规模达300万亿美元,而永续优先股市场仅约1万亿美元,这表明机构有意规避这种无还款期限的资产,将风险转嫁给信息不足的散户。 针对“比特币波动性太大”的常见观点,他认为波动性是这一供应量严格受限的新资产被大规模采用过程中的自然数学结果。新人入场需出更高价从早期持有者手中购买,导致价格剧烈波动。他建议投资者直接持有比特币,这比投资MicroStrategy等公司发行的衍生品更安全。 投资者将焦点从直接持有加密货币转向公司衍生品,会忽视法币急速贬值的真正威胁。刘易斯以自创的“肋眼牛排指数”为例,指出其本地超市一款牛排价格从2020年的19.99美元涨至37.99美元,反映年化约12-13%的真实通胀,远超官方平滑后的CPI数据。 在全球通胀环境下,最明智、保守且安全的策略仍是直接持有比特币并完全掌控私钥。追逐加密货币国库股等公司工具的收益只会叠加隐性系统风险,而理解去中心化货币的本质才能有效保护财富免受宏观经济动荡影响。

cryptonews.ru5小时前

帕克·刘易斯解释为何比特币仍是最佳货币

cryptonews.ru5小时前

交易

现货

热门文章

从H2A到A2A:AI Agent经济体与Crypto新机遇

6月17日,哈佛大学独立研究员、美国AI科学院(NAAI)通讯院士、比特币基金会终身会员韩锋做客火币HTX《大咖讲堂》第三期,以《从H2A到A2A》为主题,分享了其对Agent经济、Crypto基础设施及数字社会未来发展的思考。

537人学过发布于 2026.07.01更新于 2026.07.01

从H2A到A2A:AI Agent经济体与Crypto新机遇

美股TradFi:传统金融在AI IPO浪潮下的稳健锚点

2026年,美股IPO市场重回高热度。本文梳理即将上线或受关注的热门赛道龙头,分析具备投资潜力的交易标的及其逻辑,并探讨宏观趋势与相关风险。

2.5k人学过发布于 2026.07.08更新于 2026.07.08

美股TradFi:传统金融在AI IPO浪潮下的稳健锚点

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对AI(AI)币价的意见。

活动图片