← March 29, 2026 briefingTech
LiteLLM supply chain hack exposed thousands of AI projects
A supply chain attack on LiteLLM in March 2026 compromised every project depending on the widely-used AI infrastructure library, potentially exposing API keys, prompts, and tool calls across thousands of codebases. The breach trended on Hacker News with 395 points, and a parallel bug bounty launched by OpenAI this week — paying up to $7,500 for reproducible prompt injection findings — underscores how rapidly AI security threats are outpacing defences. Most affected projects had zero runtime security in place at the time of the attack.
Sources


