Switch card · LLM GATEWAYS

OpenRouter LiteLLM

CONFIDENCE: LOW· updated 2026-08-17· n=13 independent, 43 sources, 117-row ledger· vendor content discounted

This is a ⇄, not a migration. The acquisition is reported, not confirmed — and the same story says both things at once: Bloomberg has Stripe having “finalized an agreement… for more than $7 billion, according to people familiar with the matter” and, in the same piece, “The final price for the acquisition could change.” Stripe “doesn’t comment on rumors or speculation”; OpenRouter declined to comment; and OpenRouter shipped a routine product post on 2026-08-17, the day after Bloomberg’s story, without mentioning it. Across five stories we read, nothing states what happens to the product, the API or the pricing — so there is nothing there to act on, and a practitioner in that thread says the switching cost is low precisely because a router is thin — “as easy to switch from as the model providers they proxy” (skeledrew, HN, 2026-08-16). Meanwhile the compromise that is supposed to scare you off self-hosting happened on 2026-03-24: the packages were live about 40 minutes on PyPI, though the vendor’s own affected-install window runs 10:39–16:00 UTC — and by that same postmortem it did not touch the official Docker path or GitHub-source installs. So neither headline decides it. Spend, data residency — and, for a mainland-China developer, whether you can hold an account at all — decide it. On spend, OpenRouter’s own comparison concedes a crossover against itself — but it is a range, not a line. Its formula is infra ÷ 5.5%, and its “$200/month of infra” input is asserted with no derivation; two independent dated deployments bracket that roughly tenfold apart, putting the real crossover anywhere from about $340 to about $6,900 a month of model spend. ⚠ And if you bring your own provider keys the fee is $0 below $25,000/month — above the whole range — so for that team the fee argument mostly never starts. One careful first-hand account landed on exactly this shape: a thin gateway he controls with the rented router as its only upstream — “折腾一圈后,我还是回到了 OpenRouter…于是花了两天写了一个很薄的 OpenRouter 网关” (devlrboyz, V2EX, 2026-08-03). ⚠ That “only upstream” is his configuration, not a pattern. A Japanese operator running a related shape does the opposite with customer data: his client-* routes “は、OpenAIやAnthropicやGoogleの直APIか、ローカルのOllamaにしか結線されていません” — are wired only to the direct APIs of OpenAI, Anthropic or Google, or to local Ollama — so the rented router carries his other traffic and never his clients’ (seiryu_dev, Zenn, 2026-07-16). That buys you the seam: if ownership, pricing or routing changes, you edit one upstream instead of a fleet of callers. ⚠ Be clear about what “own the seam” costs, because this card spends its keynote on it: if the seam is a full LiteLLM deployment you inherit that patch queue — 12 advisories, 3 critical, 2 in CISA’s KEV catalogue. The account above did the opposite: two days’ work on a deliberately thin gateway whose only upstream is the rented router. And the sharpest version of that line comes from someone with every reason to say otherwise: a Japanese developer who quit LiteLLM for a single-binary Go tool of his own making still concedes “数百人の開発者が叩く社内LLMゲートウェイを構築するなら、運用実績の長いLiteLLMが圧倒的に有利です”, if you are building an in-house LLM gateway hit by hundreds of developers, LiteLLM, with its long operational track record, is overwhelmingly advantageous (okamyuji, Zenn, 2026-05-29 — ⚠ he is showcasing his own competing tool, which is why the concession counts and the recommendation does not; his article never mentions OpenRouter). A thin seam for a small team; LiteLLM for a real internal platform; and either way the routing stays rented until spend, residency or eligibility says otherwise.

The fact that decides it: the two events everyone is reacting to are five months apart, not the same week. LiteLLM’s compromised packages (1.82.7, 1.82.8) were live on PyPI 2026-03-24 for about 40 minutes before quarantine — though the vendor’s own Who is Affected window for a compromised pip install is longer, 10:39–16:00 UTC; GitHub’s advisory GHSA-5mg7-485q-xm76 is dated 2026-03-25. The August coverage wave is follow-up coverage, not a new breach — though we read that coverage only at headline level and do not restate its figures here. But re-dating that one incident is not the security story, and this card previously stopped there. BerriAI/litellm carries 12 published security advisories in 20263 critical, 5 high, 2 medium, 2 low, dated 2026-04-03 through 2026-06-30 — and one of them, CVE-2026-42271 (authenticated command execution, fixed in 1.83.7), is in CISA’s Known Exploited Vulnerabilities catalogue — and so is CVE-2026-42208, which we confirmed directly (catalogVersion 2026.08.17): two of the twelve are known exploited in the wild. That steady advisory stream, not the 40-minute PyPI window, is the operator cost of self-hosting — and it is the thing the crossover arithmetic does not price.

The decision

CHOOSE LITELLM IF →

  • Your model spend clears the crossover — and you have picked your own infra number, because the vendor’s is doing all the work. OpenRouter’s comparison concedes the arithmetic against itself: “Divide your monthly infrastructure cost by the 5.5% fee. At roughly $200/month of infra, LiteLLM gets cheaper once your model spend passes about $3,600/month” (openrouter.ai, 2026-06-19, verified verbatim). But that $200 is asserted with no derivation, and two independent dated deployments bracket it roughly 10× apart: a single Tokyo VPS at ¥3,000–6,000/month (≈$19–38 at 159.20 JPY/USD — rate fetched 2026-08-17 from exchangerate-api.com, whose time_last_update_utc reads Mon, 17 Aug 2026 00:02:31 +0000, and logged in the ledger; Zenn, 2026-04-02) and the AWS-official reference stack at $378/month, itemised across ECS, multi-AZ RDS, NAT, Redis and ALB (Zenn, 2026-07-23). Run through the vendor’s own formula those give crossovers of about $340–690 and about $6,900. So the honest answer is a range spanning an order of magnitude, and the number that decides it is yours, not theirs. Two further caveats: the formula counts infra dollars only — the vendor concedes operator labour in the next sentence — and the 5.5% is charged on credit purchases, not on inference. ⚠⚠ AND THE TERM THAT MAY CANCEL THIS WHOLE BULLET: if you bring your own provider keys, OpenRouter charges nothing until $25,000/month. Its docs FAQ, read 2026-08-17: “BYOK has a plan-dependent free allowance measured by list-price inference cost, not request count. Pay-as-you-go includes [$25,000] per month with no BYOK fee, while Enterprise includes [$200,000]. Usage above the allowance has a fee of [5]%”. $25,000/month is roughly 3.6× the TOP of the crossover range above — so for a BYOK team the fee argument for self-hosting does not begin where this bullet says it does, and mostly does not begin at all. Residency, control and eligibility still can. The fee cannot.
  • Request data cannot leave your network. By OpenRouter’s own description, requests “pass through a managed layer first”; with a self-hosted proxy they do not. If a compliance team is asking, this is the row that answers them — not the fee.
  • You need per-team keys, spend tracking and routing rules enforced inside your own infrastructure. That is the stated reason a self-hosted proxy exists, and it is the one thing a rented router structurally cannot give you.
  • You are already paying the operator cost. Self-hosting means running PostgreSQL and Docker yourself, plus Redis — and per LiteLLM’s own docs Redis is “Required once you run more than one instance” while the same docs tell you to “run 2+ replicas behind a load balancer”, so any real production deployment needs it. Then add patching: 12 security advisories in 2026. If you run that stack anyway the marginal cost is small; if you do not, the fee is buying you an on-call rotation you don’t have.
  • You want to be able to audit the code path. “如果数据特别敏感,最稳妥的选择仍然是直接使用模型官方 API ,或者自行部署一个足够薄、代码可审查的网关” — if the data is particularly sensitive, the safest choice is still the official API directly, or a gateway thin enough to audit (devlrboyz, V2EX, 2026-08-03).
  • You need what lives behind the enterprise licence — and you have read which half is free. LiteLLM’s root LICENSE is MIT (Copyright (c) 2023 Berri AI) for everything outside the enterprise/ directory; enterprise/ is governed by the separate BerriAI Enterprise License, which allows “development and testing” but requires a paid seat-based subscription for production. The crossover arithmetic assumes the MIT half only — and SSO, RBAC and audit logs are on the paid side, which is what a team at that spend usually wants.
  • You are in mainland China, where the managed router may not be available to you at all. Two independent first-hand accounts, three months apart, describe OpenRouter access failing on account and payment eligibility before spend or compliance ever come up: one lost access after a top-up with a mainland-bank Visa — “我是自动充了一次值后…就突然用不了了” — the other spent days working around email domain, billing address and payment instrument. This is the row that decides it before the fee does, and for this population it points the opposite way from the fee arithmetic.

CHOOSE OPENROUTER IF →

  • What you are actually buying is billing, not routing. “the value of openrouter is it offers centralized billing… switching to a new model, or a new provider of the same model, doesn’t mean setting up a new billing account with a new provider” (notatoad, HN, 2026-08-16). A self-hosted proxy does not solve that: “A library with a bunch of different providers doesn’t solve the payment/billing problem… worth the 5% to me” (542458, HN, 2026-05-30).
  • You priced the alternative and it cost more. “The other popular option is something like LiteLLM, which just has a major vulnerability that left a lot of big corps exposed. After spending a year trying to fight this battle, I’ve decided OpenRouter is worth their cut” (jdgoesmarching, HN, 2026-08-17). Note the card corrects his timing — that specific vulnerability is five months old — though LiteLLM carries 12 advisories dated through 2026-06-30, so this is not an argument that the component is quiet — and his conclusion still stands on the operator cost.
  • Your spend sits below the crossover. Under it, the fee is cheaper than the engineering time, by the vendor’s own arithmetic. The fee bites at the top end, not the bottom: “that 5% surcharge is meaningful at that level of cost” — said specifically of running expensive models as a full agentic backbone (minimaxir, HN, 2026-05-30).
  • The acquisition has not changed anything you call yet. It is reported, not confirmed by either party: Stripe “doesn’t comment on rumors or speculation”, OpenRouter declined to comment, and OpenRouter’s own blog posted a routine product update on 2026-08-17, the day after Bloomberg’s story, without mentioning it. The July $10B and the August $7B+ are the same number at two points in one negotiation, not a contradiction — TechCrunch chains them in a sentence, and the CEO was asked about the $10B on the record on 2026-08-10 and answered “I can’t… comment” (auto-generated captions — ASR, not an official transcript). Nothing in five stories we read says what happens to the product, API or pricing. Watching is free; migrating on a rumour is not.
  • Your risk here is not the router. The Chinese-language corpus that is most hostile to paid API middlemen explicitly exempts this class: “本文(及前文)的中转特指各种类型的廉价中转,不包括 openrouter / cloudflare ai gateway 之类的商业中转” (ImSingee, V2EX, 2026-08-08).

Works with your setup?

Where routing
runs
Platform feeYou operateSource you
can read
Public 2026
advisories
Data leaves
your network
Switching
cost
OpenRouter✗ vendor infra · Cloudflare edge✗ 5.5% PAYG · $0 BYOK <$25k/mo✓ nothing⚠ not checked this sweep⚠ not checked this sweep✗ yes · managed layer first✓ low · “easy to switch from”
LiteLLM (self-hosted)✓ your infra · Docker + Postgres✓ none · infra cost instead✗ Postgres + Redis (2+ inst) + Docker⚠ MIT, except enterprise/✗ 12 · 3 critical · 2 in CISA KEV✓ no · the proxy is yours⚠ you become the operator

Sentiment — independent voices only

The bar is POSTURE toward paying for a managed router, not sentiment about a brand — green is never assigned to either product. Keep the managed router is 6 of 13; conditional or run-both is 5; leave it is 2. Every voice is listed with handle, platform, source id and date in quotes.md §6, and every one was re-located at its own URL on 2026-08-17 — which is how two wrong author handles were caught and corrected. The roster is deliberately small and was NOT re-cut by the 2026-08-17 widened sweep. That sweep took the ledger to 117 rows, read six 小红书 notes end to end and closed the Japanese gap entirely — 21 full dated Japanese and Chinese bodies (12 Japanese, 9 Chinese) where the draft had only titles, including two first-hand operators whose accounts are cited above — but n stays 13 on purpose: the new first-hand voices speak to access eligibility, hidden cost and infrastructure cost — different axes — and of the four Japanese first-hand operators read, only one states a posture toward paying for a managed router. The rule applied, stated so it can be checked: the roster is the 2026-08-17 HN+V2EX cut, and a voice found after that cut is quoted on the card face but is NOT folded into the bar — including a Japanese operator who runs both, though he keeps customer data off the rented router entirely. That under-claims n by at least one on purpose, and the two 小红书 notes that do address the crossover were both refused as independent voices, for two different strengths of reason. 遥遥领先 (2026-06-22) is the strong case: three days after the vendor page, landing on its rounded $3,600 artefact, dropping the $200 premise, and carrying a vendor term that page states differently. TechMemo (2026-06-24) is the weaker case and is labelled as such: it carries zero arithmetic — it reproduces the vendor page’s axes five days later, which is suggestive of provenance but does not prove it. Counting them would have inflated n with the vendor’s own number wearing a third-party badge. Reddit and X contribute zero to THIS BAR — but for two different reasons, and the distinction matters. The ~18 mirror-only Reddit handles are excluded as unverifiable. The two Reddit threads and two X posts read directly through agent-reach on 2026-08-17 are outside the frozen roster, under the same rule as the Japanese operators — including u/Particular-Room8732, a first-hand operator who landed on the self-hosted side. He is quoted on the card face and would move the bar away from “keep the managed router” if folded in; leaving him out under-claims in the direction that costs this card.

Weighted evidence

Show all 27 sourcesShow fewer

Why confidence is LOW

the compromise was 2026-03-24 — ~40 min live on PyPI, 5h21m install window the official Docker path and GitHub-source installs were not impacted — vendor's own claim LiteLLM: 12 security advisories in 2026, 3 critical, 2 in CISA KEV the $3,600 crossover assumes a $200 infra figure the vendor never derives the 5.5% fee was announced 2025-06-09 — it is not new LiteLLM is MIT — except enterprise/, which needs paid seats for production $10B in July and $7B+ in August are ONE deal repriced, not a contradiction as of 2026-08-17 neither Stripe nor OpenRouter has confirmed the deal Reddit and X contribute zero to the BAR — n=13 is the frozen HN + V2EX roster

Coverage — what we read, what we skipped

⚠ THIS CARD WAS SWEPT TWICE, AND THE FIRST SWEEP HAD NO agent-reach. The scheduled cloud builder that drafted it could not call mcp__agent-reach__* at all — verbatim, No matching deferred tools found — with WebFetch returning {"error_type":"PROVENANCE_REQUIRED"} and Reddit 403, so the draft rested on HN + V2EX only. It was re-swept on 2026-08-17 from a machine where agent-reach works, and that second sweep falsified five claims the draft carried: the BYOK terms (“first 1M requests/month waived” — the allowance is a dollar figure and the docs say explicitly “not request count”), the licence (recorded as unknowable; the file reads clean), “optional Redis” (LiteLLM’s own docs say required past one instance), the claim that no source reconciled $10B with $7B+ (TechCrunch reconciles them in one sentence), and the Bloomberg slug cited as evidence of “nears” (the page as rendered says “Clinches”). Those corrections are the main thing that changed; the verdict did not.
READ — PRIMARY AND MACHINE-CHECKABLE: BerriAI’s own postmortem; GitHub advisory GHSA-5mg7-485q-xm76; all 12 of BerriAI/litellm’s 2026 security advisories via api.github.com (HTTP 200 — it did not 403 from this machine, unlike the cloud run); incident issue #24518; the root LICENSE and enterprise/LICENSE.md (via gh api; raw.githubusercontent.com returned 429: Too Many Requests, a workaround rather than a gap); repos.ecosyste.ms; LiteLLM’s own deploy/prod/quickstart docs; OpenRouter’s pricing page, docs FAQ, 2025-06-09 fee post and 2026-06-19 comparison; and openrouter.ai/announcements plus stripe.com/newsroom, both read 2026-08-17 to establish that neither company has posted about the deal. Johann Rehberger’s research was read at the primary after the draft cited it second-hand through an X post behind a t.co link — and the primary is materially weaker than the relay implied. ENGLISH FORUMS: HN threads are each cited with their own count and never summed; eight comments were re-fetched at their own permalinks. ⚠ The original sweep cited 9 threads on Hacker News — six from the August acquisition window and three from June — with March missing from all 9, so it missed the news cycle the story actually broke in, including the 938-point / 496-comment thread that is the most-discussed LiteLLM story on HN. Those threads were added on 2026-08-17 after a verifier ran the endpoint this card already cited and found them in its top four. The lesson is recorded rather than smoothed over: a sweep anchored on one news window will miss the window the story actually broke in. 中文: three V2EX threads (cached Exa render — reply lists are as rendered, view counts are the snapshot’s, so not a full-thread read; the one quoted sentence was re-read live at v2ex.com on 2026-08-17 to settle a splice); six 小红书 notes read end to end on signed URLs — note the limit: that is the note body in each case, not the comment threads under them (one carries 108 comments, none of which were read) (the draft had read two and logged four as titles); all four B站 items now carry a publish date, view/like/favourite/reply counts and the uploader-written description — we cite only the title, the uploader-written description and the counts from all four, and quote no spoken content from any of them — this project’s standing rule for B站, applied here as a self-imposed limit rather than a finding: we did not query a subtitle endpoint for these four and make no claim about what one would return. ALSO: a 20VC interview in which OpenRouter’s CEO is asked about the $10B on the record and declines to answer — auto-generated captions (ASR), flagged as such wherever used.
NOT REACHED — TRIED, FAILED, ERROR QUOTED: The Wall Street Journal, the primary behind the entire July $10B figure, failed on three routes: WebFetch Claude Code is unable to fetch from www.wsj.com; Jina Reader Warning: This page maybe requiring CAPTCHA, please make sure you are authorized to access this page.; archive.ph Warning: Target URL returned error 429: Too Many Requests. bloomberg.com itself: The server returned HTTP 403 Forbidden. (Bloomberg Law carries the same story and did load, paywall-cut mid-sentence; Fortune’s syndication supplied the missing paragraph.) X — PARTLY read, and the earlier wording here was wrong. Two X posts were read at their own URLs through agent-reach on 2026-08-17 and are quoted in the receipts; what failed was the profile page x.com/OpenRouter, The server returned HTTP 402 Payment Required. So X is a partial gap — no profile-level sweep — not an unreached platform. Reddit — and this footer previously misdescribed it. The scheduled cloud builder failed on Reddit entirely (httpStatusCode 403, tag SOURCE_NOT_AVAILABLE seven times; No active connection found for toolkit(s) 'reddit' in this session.), and the ~18 handles reachable only through an unverifiable third-party mirror were all excluded and remain excluded. But two Reddit threads WERE later read at their own URLs through agent-reach on 2026-08-17, and one of them is a first-hand operator who chose the self-hosted side — he is quoted on this card. He is outside the frozen n=13 roster under the same rule applied to the Japanese operators, not because he was unreachable. Saying otherwise would have quietly tilted the bar toward the managed router. 日本語 AND THE CHINESE DEV BLOGS — THE DRAFT’S BIGGEST GAP, NOW CLOSED. The first sweep reached Japanese articles but could retrieve titles only, so Japanese contributed zero voices. That was a tooling failure, not an empty corpus. Zenn and Qiita both expose article APIs that return the full body with an exact publication timestamp; 掘金 enumerates through its search API with bodies via a reader proxy — the draft’s “Please wait...” shell was a direct-fetch artefact only; and note.com returns full JSON once a User-Agent header is sent, which is almost certainly what blocked the earlier attempt. 21 full dated bodies were read this way12 Japanese (8 Zenn, 2 Qiita, 2 note.com) and 9 Chinese (5 掘金, 3 知乎, 1 博客园), and they produced the single most important finding of the re-sweep: two independent itemised infrastructure figures that bracket the vendor’s crossover assumption about tenfold. 知乎 is a PARTIAL gap, not a blanket one: its search endpoint is CAPTCHA-walled — HTTP/2 403, then via a reader proxy Title: 安全验证 - 知乎 and Warning: This page maybe requiring CAPTCHA, please make sure you are authorized to access this page. — and the CAPTCHA was deliberately not attempted, because defeating bot-detection is out of bounds for this project; individual 知乎 column articles read fine about half the time, and the failures were one 403: Forbidden, one removed article and one login wall. CSDN is paywalled: 最低0.47元/天 解锁文章, intro only. What the Japanese corpus did NOT contain is as useful as what it did: across ~80 Zenn/Qiita/note titles and 10 full Japanese bodies, the 5.5% platform fee is mentioned zero times — including by authors who had topped up OpenRouter credit — so this card does not claim the fee is common knowledge. Excluded and named: an SEO comparison cross-posted verbatim to two platforms (one source, not two), roughly ten machine-generated near-identical Qiita posts, a Zenn piece that is a self-declared translation of a Reddit post, and a note.com analysis whose author sells a competing router. One follow-up is named and not carried: a Japanese company’s engineering blog on AI token-cost governance (2026-08-09) was found title-only and its body was not read. DELIBERATELY NOT FETCHED, and named so the omission is visible: Sonatype’s analysis of the PyPI compromise, Obsidian Security’s privilege-escalation write-up, issue #24512, the two walkthrough videos embedded in the Rehberger post. CISA’s KEV catalogue WAS fetched (catalogVersion 2026.08.17) after a verifier pointed out that a one-request public JSON was changing a number on the card face: it holds two LiteLLM entries where the card had said one, and the card now states two as our own finding rather than as a researcher’s claim.
WATCH OUT — WHAT THIS CARD STILL DOES NOT KNOW: The roster is two platforms, not eight. n=13 is HN and V2EX only and was deliberately not re-cut by the second sweep — it is an under-claimed subset, never a saturation census. The two 小红书 notes that appear to corroborate the $3,600 crossover were refused as independent voices: both are dated within five days after OpenRouter’s own comparison page — and they are refused on different strengths of evidence: one lands on the vendor’s rounded $3,600 artefact and drops the $200 premise the figure depends on, while the other carries zero arithmetic and is refused only for reproducing the same axes days later, which is weaker and is stated as weaker — counting them would have put the vendor’s number on this card wearing a third-party badge. The 2026-03 Chinese security corpus is cited as a dated cluster of 14 notes, never as 14 voices — it is one news event summarised many times. The B站 corpus around LiteLLM is substantially replacement marketing (titles promising 「比 LiteLLM 快 50 倍」 and 「快 14.5 倍」 — 50× and 14.5× faster than LiteLLM), and every such figure is treated as an unmethodologised uploader assertion and kept off the card face. An unresolved 13-minute hole sits in the incident timeline — the vendor says the packages went live at 10:39 UTC, an independent write-up says v1.82.8 was uploaded at 10:52 — so this card asserts no single upload instant. This card also states no root cause for the compromise, because the incident issue contradicts itself between its maintainer block and its own summary, and the analysis that might settle it was not fetched. Counts drift within a single day — HN 49323381 read 301/199, then 328/205, then 332/205 across three passes on 2026-08-17 — so every count here is as read, never a fact about the thread. Press scale figures are quoted only as thread titles, never asserted as findings. The underlying figures: 2,488 organisations, 153GB and 434,000 pipelines were seen at headline level only, and the two outlets’ user/model counts disagree with each other. Nothing anywhere states what happens to OpenRouter’s product, API or pricing after the reported acquisition — that was checked across five stories, and this card therefore makes no claim about it. ⚠ The 小红书 links on this card will not open for you. Those notes are reachable only through signed URLs whose tokens expire; the durable key is the note id plus author plus a verbatim substring, all of which are in the receipts, and the bare links are retained so the id is visible. This is a property of the platform, not a paywall. ⚠ Only 64 of the 117 ledger rows carry a date field — the other 53 are almost all rows the original scheduled builder wrote without one, and dates were never invented to fill them. Every source cited on the card face carries a publication date, a read date, or both in its own citation line; but the ledger behind it is only about half dated, and a reader auditing all 117 rows will see that. Confidence is LOW, and that is the honest level for a card whose central commercial fact is a deal neither party will confirm.

Show every source we read (117) Hide the ledger

The 117 sources in this card's ledger — 49 of them quoted above. Sources we read and did not quote are listed too, with why. This is the ledger, not a claim of exhaustiveness: anything the sweep read but deliberately left out of it is named in the coverage note above, with the reason. Reliability and neutrality are our own scores, not the publisher's. Vendor-owned pages are marked in the notes and never carry the verdict.

Straight answers

when was the litellm supply chain attack?
2026-03-24, not August. The compromised packages litellm==1.82.7 and 1.82.8 were live on PyPI for about 40 minutes before quarantine, per BerriAI’s own postmortem — which separately puts the window in which a pip install could have been affected at 10:39–16:00 UTC that day — and GitHub’s advisory GHSA-5mg7-485q-xm76 is dated 2026-03-25. Fourteen Chinese-language notes independently date it to 2026-03-25/26/27. The August 2026 news wave is follow-up coverage, not a new compromise; this card read that coverage at headline level only and carries none of its figures. This card states no root cause — the incident issue contradicts itself on that point.
was i affected by the litellm breach?
The window that matters is longer than the one in the headlines. BerriAI’s postmortem says you may be affected if “You installed or upgraded LiteLLM via pip on March 24, 2026, between 10:39 UTC and 16:00 UTC” — 5h21m, not the ~40 minutes the packages were live on PyPI, and not only if you were unpinned: the same section names unpinned transitive dependencies (through agent frameworks, MCP servers or orchestration tools) and Docker images built during the window that ran pip install litellm unpinned. Installing was enough on its own — the payload ran on install, not on import. Not affected: the official LiteLLM Proxy Docker image, which “pins dependencies in requirements.txt”, and installs from the GitHub repository, which was “not compromised”. If you were inside that window, the postmortem’s instruction is to rotate every credential the environment could see.
does openrouter charge a fee?
Yes — 5.5% on pay-as-you-go credit purchases with a $0.80 minimum, and 5.0% on crypto, confirmed live on OpenRouter’s own pages. Two caveats this card checked: the $0.80 minimum and the crypto rate are not on the pricing page at all — they live in the docs FAQ — and “Fee discounts available” appears only in the Enterprise cell — the pay-as-you-go cell is a flat 5.5%, and the same page says “We do not discount inference.” And the exception that matters most: bring your own provider keys and OpenRouter charges nothing below $25,000/month. Verbatim: “BYOK has a plan-dependent free allowance measured by list-price inference cost, not request count. Pay-as-you-go includes [$25,000] per month with no BYOK fee, while Enterprise includes [$200,000].” Separately, a “free” model can still bill you for tool calls: one first-hand account lost ten-odd dollars to the OCR path on a few PDFs.
is litellm cheaper than openrouter?
It depends on spend and on an infrastructure figure the vendor never justifies. OpenRouter’s own comparison says that at roughly $200/month of infrastructure, self-hosted LiteLLM gets cheaper once model spend passes about $3,600/month. But two independent dated deployments put real infra about 10× apart — about $19–38/month for a single VPS (¥3,000–6,000 at 159.20 JPY/USD, rate fetched 2026-08-17) and $378/month for the AWS-official reference stack — which through the same formula gives crossovers from roughly $340 to roughly $6,900 a month. Across 21 posts swept for this card — 12 Japanese, 9 Chinese — the $3,600 figure is never independently reproduced; it stays vendor-sourced. Treat it as a range you compute from your own infra bill, not a threshold. And check one term before you compute anything: if you bring your own provider keys, OpenRouter charges nothing below $25,000/month of list-price inference ($200,000 on Enterprise), 5% above it. That allowance sits well above the top of the range, so for a BYOK team the fee case for self-hosting mostly does not arise.
is litellm open source? what licence is it?
MIT — with one carve-out. LiteLLM’s root LICENSE reads: everything outside the enterprise/ directory is “available under the MIT license” (Copyright (c) 2023 Berri AI); enterprise/ is governed by the separate BerriAI Enterprise License, which permits development and testing but requires a paid seat-based subscription for production use. GitHub and repos.ecosyste.ms both report the licence field as other/NOASSERTION — that is a detection artefact caused by the carve-out preamble, not an unclear licence.
is litellm safe to self-host?
That is the operator cost, and it is larger than the fee debate suggests. BerriAI/litellm has 12 published security advisories in 20263 critical, 5 high, 2 medium, 2 low — dated 2026-04-03 through 2026-06-30. One, CVE-2026-42271, let any authenticated user run arbitrary commands on the host because the endpoints had “no role check”; it is fixed in 1.83.7. Two of the twelve are in CISA’s Known Exploited Vulnerabilities catalogue — CVE-2026-42208 and CVE-2026-42271 — meaning exploitation observed in the wild. Self-hosting means you own that patch queue, and the crossover arithmetic — whose range runs from roughly $340 to roughly $6,900 a month depending on your infrastructure bill — does not price it at all.
did stripe buy openrouter?
Reported, not confirmed. Bloomberg reported on 2026-08-16 that Stripe had “finalized an agreement” at more than $7 billion, “according to people familiar with the matter” — while saying in the same story that “The final price for the acquisition could change”. Stripe “doesn’t comment on rumors or speculation”, OpenRouter declined to comment, and OpenRouter’s own blog published a routine product post the next morning without mentioning it. The ~$10B reported in July and the $7B+ in August are the same deal repriced, not two conflicting figures.
should i leave openrouter because of the stripe acquisition?
Nothing in this sweep shows the API changing — across five stories we read, none states what happens to the product, the API or the pricing. A practitioner in that thread says the switching cost is low precisely because a router is thin — “as easy to switch from as the model providers they proxy”. So the acquisition is a reason to watch, not to migrate. Spend, data residency, and — if you are in mainland China — account and payment eligibility are what actually decide it.

Stuck on a different switch?

If the card doesn't exist yet, request it — free, like everything here. Full sweep, weighted verdict, and one email the moment it's published.

Request a card