OpenRouter ⇄ LiteLLM
Five drafted claims falsified; three misquotes repaired.
Own the seam — rent the router.
This is a ⇄, not a migration. The acquisition is reported, not confirmed — and the same story says both things at once: Bloomberg has Stripe having “finalized an agreement… for more than $7 billion, according to people familiar with the matter” and, in the same piece, “The final price for the acquisition could change.” Stripe “doesn’t comment on rumors or speculation”; OpenRouter declined to comment; and OpenRouter shipped a routine product post on 2026-08-17, the day after Bloomberg’s story, without mentioning it. Across five stories we read, nothing states what happens to the product, the API or the pricing — so there is nothing there to act on, and a practitioner in that thread says the switching cost is low precisely because a router is thin — “as easy to switch from as the model providers they proxy” (skeledrew, HN, 2026-08-16). Meanwhile the compromise that is supposed to scare you off self-hosting happened on 2026-03-24: the packages were live about 40 minutes on PyPI, though the vendor’s own affected-install window runs 10:39–16:00 UTC — and by that same postmortem it did not touch the official Docker path or GitHub-source installs. So neither headline decides it. Spend, data residency — and, for a mainland-China developer, whether you can hold an account at all — decide it. On spend, OpenRouter’s own comparison concedes a crossover against itself — but it is a range, not a line. Its formula is infra ÷ 5.5%, and its “$200/month of infra” input is asserted with no derivation; two independent dated deployments bracket that roughly tenfold apart, putting the real crossover anywhere from about $340 to about $6,900 a month of model spend. ⚠ And if you bring your own provider keys the fee is $0 below $25,000/month — above the whole range — so for that team the fee argument mostly never starts. One careful first-hand account landed on exactly this shape: a thin gateway he controls with the rented router as its only upstream — “折腾一圈后,我还是回到了 OpenRouter…于是花了两天写了一个很薄的 OpenRouter 网关” (devlrboyz, V2EX, 2026-08-03). ⚠ That “only upstream” is his configuration, not a pattern. A Japanese operator running a related shape does the opposite with customer data: his client-* routes “は、OpenAIやAnthropicやGoogleの直APIか、ローカルのOllamaにしか結線されていません” — are wired only to the direct APIs of OpenAI, Anthropic or Google, or to local Ollama — so the rented router carries his other traffic and never his clients’ (seiryu_dev, Zenn, 2026-07-16). That buys you the seam: if ownership, pricing or routing changes, you edit one upstream instead of a fleet of callers. ⚠ Be clear about what “own the seam” costs, because this card spends its keynote on it: if the seam is a full LiteLLM deployment you inherit that patch queue — 12 advisories, 3 critical, 2 in CISA’s KEV catalogue. The account above did the opposite: two days’ work on a deliberately thin gateway whose only upstream is the rented router. And the sharpest version of that line comes from someone with every reason to say otherwise: a Japanese developer who quit LiteLLM for a single-binary Go tool of his own making still concedes “数百人の開発者が叩く社内LLMゲートウェイを構築するなら、運用実績の長いLiteLLMが圧倒的に有利です”, if you are building an in-house LLM gateway hit by hundreds of developers, LiteLLM, with its long operational track record, is overwhelmingly advantageous (okamyuji, Zenn, 2026-05-29 — ⚠ he is showcasing his own competing tool, which is why the concession counts and the recommendation does not; his article never mentions OpenRouter). A thin seam for a small team; LiteLLM for a real internal platform; and either way the routing stays rented until spend, residency or eligibility says otherwise.
1.82.7, 1.82.8) were live on PyPI 2026-03-24 for about 40 minutes before quarantine — though the vendor’s own Who is Affected window for a compromised pip install is longer, 10:39–16:00 UTC; GitHub’s advisory GHSA-5mg7-485q-xm76 is dated 2026-03-25. The August coverage wave is follow-up coverage, not a new breach — though we read that coverage only at headline level and do not restate its figures here. But re-dating that one incident is not the security story, and this card previously stopped there. BerriAI/litellm carries 12 published security advisories in 2026 — 3 critical, 5 high, 2 medium, 2 low, dated 2026-04-03 through 2026-06-30 — and one of them, CVE-2026-42271 (authenticated command execution, fixed in 1.83.7), is in CISA’s Known Exploited Vulnerabilities catalogue — and so is CVE-2026-42208, which we confirmed directly (catalogVersion 2026.08.17): two of the twelve are known exploited in the wild. That steady advisory stream, not the 40-minute PyPI window, is the operator cost of self-hosting — and it is the thing the crossover arithmetic does not price.
The decision
CHOOSE LITELLM IF →
- Your model spend clears the crossover — and you have picked your own infra number, because the vendor’s is doing all the work. OpenRouter’s comparison concedes the arithmetic against itself: “Divide your monthly infrastructure cost by the 5.5% fee. At roughly $200/month of infra, LiteLLM gets cheaper once your model spend passes about $3,600/month” (openrouter.ai, 2026-06-19, verified verbatim). But that $200 is asserted with no derivation, and two independent dated deployments bracket it roughly 10× apart: a single Tokyo VPS at ¥3,000–6,000/month (≈$19–38 at 159.20 JPY/USD — rate fetched 2026-08-17 from exchangerate-api.com, whose
time_last_update_utcreads Mon, 17 Aug 2026 00:02:31 +0000, and logged in the ledger; Zenn, 2026-04-02) and the AWS-official reference stack at $378/month, itemised across ECS, multi-AZ RDS, NAT, Redis and ALB (Zenn, 2026-07-23). Run through the vendor’s own formula those give crossovers of about $340–690 and about $6,900. So the honest answer is a range spanning an order of magnitude, and the number that decides it is yours, not theirs. Two further caveats: the formula counts infra dollars only — the vendor concedes operator labour in the next sentence — and the 5.5% is charged on credit purchases, not on inference. ⚠⚠ AND THE TERM THAT MAY CANCEL THIS WHOLE BULLET: if you bring your own provider keys, OpenRouter charges nothing until $25,000/month. Its docs FAQ, read 2026-08-17: “BYOK has a plan-dependent free allowance measured by list-price inference cost, not request count. Pay-as-you-go includes [$25,000] per month with no BYOK fee, while Enterprise includes [$200,000]. Usage above the allowance has a fee of [5]%”. $25,000/month is roughly 3.6× the TOP of the crossover range above — so for a BYOK team the fee argument for self-hosting does not begin where this bullet says it does, and mostly does not begin at all. Residency, control and eligibility still can. The fee cannot. - Request data cannot leave your network. By OpenRouter’s own description, requests “pass through a managed layer first”; with a self-hosted proxy they do not. If a compliance team is asking, this is the row that answers them — not the fee.
- You need per-team keys, spend tracking and routing rules enforced inside your own infrastructure. That is the stated reason a self-hosted proxy exists, and it is the one thing a rented router structurally cannot give you.
- You are already paying the operator cost. Self-hosting means running PostgreSQL and Docker yourself, plus Redis — and per LiteLLM’s own docs Redis is “Required once you run more than one instance” while the same docs tell you to “run 2+ replicas behind a load balancer”, so any real production deployment needs it. Then add patching: 12 security advisories in 2026. If you run that stack anyway the marginal cost is small; if you do not, the fee is buying you an on-call rotation you don’t have.
- You want to be able to audit the code path. “如果数据特别敏感,最稳妥的选择仍然是直接使用模型官方 API ,或者自行部署一个足够薄、代码可审查的网关” — if the data is particularly sensitive, the safest choice is still the official API directly, or a gateway thin enough to audit (devlrboyz, V2EX, 2026-08-03).
- You need what lives behind the enterprise licence — and you have read which half is free. LiteLLM’s root
LICENSEis MIT (Copyright (c) 2023 Berri AI) for everything outside theenterprise/directory;enterprise/is governed by the separate BerriAI Enterprise License, which allows “development and testing” but requires a paid seat-based subscription for production. The crossover arithmetic assumes the MIT half only — and SSO, RBAC and audit logs are on the paid side, which is what a team at that spend usually wants. - You are in mainland China, where the managed router may not be available to you at all. Two independent first-hand accounts, three months apart, describe OpenRouter access failing on account and payment eligibility before spend or compliance ever come up: one lost access after a top-up with a mainland-bank Visa — “我是自动充了一次值后…就突然用不了了” — the other spent days working around email domain, billing address and payment instrument. This is the row that decides it before the fee does, and for this population it points the opposite way from the fee arithmetic.
CHOOSE OPENROUTER IF →
- What you are actually buying is billing, not routing. “the value of openrouter is it offers centralized billing… switching to a new model, or a new provider of the same model, doesn’t mean setting up a new billing account with a new provider” (notatoad, HN, 2026-08-16). A self-hosted proxy does not solve that: “A library with a bunch of different providers doesn’t solve the payment/billing problem… worth the 5% to me” (542458, HN, 2026-05-30).
- You priced the alternative and it cost more. “The other popular option is something like LiteLLM, which just has a major vulnerability that left a lot of big corps exposed. After spending a year trying to fight this battle, I’ve decided OpenRouter is worth their cut” (jdgoesmarching, HN, 2026-08-17). Note the card corrects his timing — that specific vulnerability is five months old — though LiteLLM carries 12 advisories dated through 2026-06-30, so this is not an argument that the component is quiet — and his conclusion still stands on the operator cost.
- Your spend sits below the crossover. Under it, the fee is cheaper than the engineering time, by the vendor’s own arithmetic. The fee bites at the top end, not the bottom: “that 5% surcharge is meaningful at that level of cost” — said specifically of running expensive models as a full agentic backbone (minimaxir, HN, 2026-05-30).
- The acquisition has not changed anything you call yet. It is reported, not confirmed by either party: Stripe “doesn’t comment on rumors or speculation”, OpenRouter declined to comment, and OpenRouter’s own blog posted a routine product update on 2026-08-17, the day after Bloomberg’s story, without mentioning it. The July $10B and the August $7B+ are the same number at two points in one negotiation, not a contradiction — TechCrunch chains them in a sentence, and the CEO was asked about the $10B on the record on 2026-08-10 and answered “I can’t… comment” (auto-generated captions — ASR, not an official transcript). Nothing in five stories we read says what happens to the product, API or pricing. Watching is free; migrating on a rumour is not.
- Your risk here is not the router. The Chinese-language corpus that is most hostile to paid API middlemen explicitly exempts this class: “本文(及前文)的中转特指各种类型的廉价中转,不包括 openrouter / cloudflare ai gateway 之类的商业中转” (ImSingee, V2EX, 2026-08-08).
Works with your setup?
| Where routing runs | Platform fee | You operate | Source you can read | Public 2026 advisories | Data leaves your network | Switching cost | |
|---|---|---|---|---|---|---|---|
| OpenRouter | ✗ vendor infra · Cloudflare edge | ✗ 5.5% PAYG · $0 BYOK <$25k/mo | ✓ nothing | ⚠ not checked this sweep | ⚠ not checked this sweep | ✗ yes · managed layer first | ✓ low · “easy to switch from” |
| LiteLLM (self-hosted) | ✓ your infra · Docker + Postgres | ✓ none · infra cost instead | ✗ Postgres + Redis (2+ inst) + Docker | ⚠ MIT, except enterprise/ | ✗ 12 · 3 critical · 2 in CISA KEV | ✓ no · the proxy is yours | ⚠ you become the operator |
Sentiment — independent voices only
Weighted evidence
- The timeline correction the whole card rests on, from the affected project’s own postmortem: “The compromised PyPI packages were litellm==1.82.7 and litellm==1.82.8. Those packages were live on March 24, 2026 from 10:39 UTC for about 40 minutes before being quarantined by PyPI.” And the scope every headline drops: “Customers running the official LiteLLM Proxy Docker image were not impacted.” Also stated: installs from the GitHub repository “was not compromised”. ⚠ TWO DIFFERENT WINDOWS, AND THE SHORTER ONE IS NOT THE ONE THAT DECIDES YOUR EXPOSURE. The packages were live on PyPI about 40 minutes; but BerriAI’s own Who is Affected section says you may be affected if “You installed or upgraded LiteLLM via
pipon March 24, 2026, between 10:39 UTC and 16:00 UTC” — a 5-hour-21-minute window. Two more exposure paths from the same section, which the card had not carried: an unpinned TRANSITIVE dependency — “A dependency in your project pulled in LiteLLM as a transitive, unpinned dependency (for example through AI agent frameworks, MCP servers, or LLM orchestration tools)” — and a Docker image built during the window that itself ran an unpinnedpip install litellm. And the remediation, verbatim: “Rotate all secrets” — “Treat any credentials present on the affected systems as compromised”, which the postmortem then itemises as API keys, cloud access keys, database passwords, SSH keys, Kubernetes tokens, and any secrets in environment variables or config files. Two further details the headlines drop, and the reason this matters to a reader checking their own exposure: the payload rode Python’s.pthauto-execution, so an unpinnedpip installin the window was sufficient — importing the library was never required; and the postmortem’s own instruction to anyone who did is to rotate every credential the environment could see. docs.litellm.ai · Security Update: Suspected Supply Chain Incident · published 2026-03-24, last updated 2026-03-27 · read 2026-08-17 · ⚠ VENDOR (the affected project) — used for facts, never the verdict - Corroborated independently of the vendor. GitHub’s advisory: Critical, “Published Mar 25, 2026… Updated Mar 27, 2026”, affected range “>= 1.82.7, <= 1.82.8”, CWE-506, and — against several security-vendor write-ups — “CVE ID · No known CVE”. Tenable’s plugin 304806 attributes CVE-2026-33634 to the same GHSA; we could not adjudicate, so this card asserts no CVE number. github.com/advisories/GHSA-5mg7-485q-xm76 · read 2026-08-17 · discrepancy: tenable.com plugin 304806
- ⚠ THE CORRECTION THIS CARD IS MOST EMBARRASSED BY: it claimed the security story drew no discussion, and the HN endpoint it cited returns the opposite in its top four results. Ranked by points,
query=litellm&tags=story(re-run 2026-08-17): 938 points / 496 comments — “Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised” (47501426, 2026-03-24, the day it happened); 441 / 147 — “My minute-by-minute response to the LiteLLM malware attack” (47531967); 151 / 31 — “Mercor says it was hit by cyberattack tied to compromise LiteLLM” (47596739). The compromise is the most-discussed LiteLLM story in HN’s history. The 6-point / 0-comment thread this card had called “the breach” is an August follow-up (49279862, 2026-08-12) that drew nothing because the argument was had in March. One thread per line, never summed — and 47501729 (739 points) is NOT a fourth signal: its comment count is 1 because a moderator merged it — “Comments moved to…47501426, which was posted first.” hn.algolia.com · the same endpoint this card cited for the retired claim · re-run 2026-08-17 — the API reportsexhaustiveNbHits:false, so no total is quoted here · HN 47501426 · 2026-03-24 · HN 47531967 · 2026-03-26 · counts as read 2026-08-17; HN counts drift within the day - The best independent first-hand account did BOTH, and it is the card’s verdict in one sentence. After abandoning cheap resellers: “折腾一圈后,我还是回到了 OpenRouter 。原因并不复杂:模型比较全,价格和上游信息相对容易核对…” — in the end I came back to OpenRouter; the model coverage is fairly complete and prices and upstream info are relatively easy to check — then: “于是花了两天写了一个很薄的 OpenRouter 网关…上游只有 OpenRouter” — so I spent two days writing a very thin OpenRouter gateway… the only upstream is OpenRouter. He also refuses to over-claim: “仅凭某一次回答质量下降,不能证明服务商一定替换了模型”. v2ex.com/t/1231697 · devlrboyz · 2026-08-03 · original read from a CACHED Exa snapshot; the quoted sentence RE-READ LIVE at v2ex.com 2026-08-17 (985 views is the snapshot’s figure; the render is not a full-thread read)
- The fee, from OpenRouter’s own pages — and two of the three numbers do not live where the card used to say. The 5.5% platform fee is confirmed live on 2026-08-17 on three OpenRouter surfaces (pricing page, docs FAQ, and the 2026-06-19 comparison) — it is not stale. But the $0.80 minimum and the 5.0% crypto rate are absent from the live pricing page entirely (zero matches for “0.80”, “minimum fee” or “markup” across its full 258KB); their live home is the docs FAQ: “OpenRouter charges a 5.5% ($0.80 minimum) fee when you purchase credits… Crypto payments are charged a fee of 5%.” And 5.5% is a list rate on ENTERPRISE ONLY — the live pricing page carries “Fee discounts available” in the Enterprise cell of the Platform Fees row and not in the pay-as-you-go cell, which reads a flat 5.5%. The same page adds “We do not discount inference.” So for the pay-as-you-go reader this crossover is written for, 5.5% is the rate, not a starting point. ⚠⚠ The largest caveat of all, and the one this card omitted until its fourth verification round: BYOK is FREE below a dollar allowance. “BYOK has a plan-dependent free allowance measured by list-price inference cost, not request count. Pay-as-you-go includes [$25,000] per month with no BYOK fee, while Enterprise includes [$200,000]. Usage above the allowance has a fee of [5]%” — the bracketed values are template constants that render as those figures. A team on its own keys under $25,000/month of list-price inference pays OpenRouter nothing. openrouter.ai/docs/faq · read 2026-08-17 · openrouter.ai/pricing · read 2026-08-17 · the page is itself undated — a grep of its full 258KB of markup returns an explicitly empty result for any published/updated field (machine-checkable, re-run it yourself), so the only date we can attach is our capture date · ⚠ BOTH VENDOR — facts only
- The security research the card used to cite second-hand — now read at the primary, and it says less than the relay implied. Johann Rehberger, 2026-08-03: “Using nothing but legitimate LiteLLM management functionality, an attacker can reroute requests, observe resolved provider credentials, collect prompts and responses, and modify requests or responses, including tool calls.” But the author bounds it himself, and the bounds are the story: “The routing change itself is not a vulnerability, but finding the credential to make the calls usually is!”; it assumes the attacker already holds the
LITELLM_MASTER_KEY(“we assume no code execution on the victim LiteLLM server… We explore a different path”); it “does not by itself bypass client-side tool authorization”; and “applies, in principle, to other AI gateway products” — it is not a LiteLLM-only liability. No CVE, no GHSA, no affected version range. This is a post-exploitation technique, not an entry point, and it is not the March PyPI incident. embracethered.com · “LLM Heist: Hijacking LiteLLM…” · published 2026-08-03 · METHOD: fetched as raw HTML (HTTP 200, 32,526 bytes) and read end to end 2026-08-17; date cross-checked three ways (og:article:published_time, the visible byline, the RSSpubDate). LIMIT: the post’s two embedded walkthrough videos were not transcribed, so anything demonstrated only on screen is outside what we read. · the card previously cited this only through an X post behind at.colink — that relay overstated it - The operator cost the crossover arithmetic does not price.
BerriAI/litellmhas 12 published security advisories in 2026 — 3 critical — all three named here (CVE-2026-35030 auth bypass, CVE-2026-42208 SQL injection in proxy API-key verification, CVE-2026-49468 auth bypass via host-header injection) — plus 5 high, 2 medium, 2 low — dated 2026-04-03 to 2026-06-30. On CVE-2026-42271: “The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host.” Affected>= 1.74.2, < 1.83.7; fixed in1.83.7. Self-hosting means you own this patch queue. github.com/advisories · GHSA-v4p8-mg3p-g94g / CVE-2026-42271 · read 2026-08-17 · full list of 12 from api.github.com · read 2026-08-17 (HTTP 200, did not 403) · KEV confirmed directly against CISA’s catalogue ·catalogVersion 2026.08.17, read 2026-08-17 — 2 LiteLLM entries (CVE-2026-42208 added 2026-05-08, CVE-2026-42271 added 2026-06-08) - A decider the English-language corpus never surfaces: whether you can hold the account at all. Two independent first-hand 小红书 accounts, three months apart. 2026-04-17, the highest-engagement on-topic note in the corpus (197 likes / 108 comments): “我是自动充了一次值后(用的国内行的visa),就突然用不了了。可能它是根据最新的账单地址来的” — after one automatic top-up (using a Visa from a mainland bank) it suddenly stopped working; maybe it goes by the latest billing address. 2026-07-13, independently: pitfalls 1–3 are the registration email domain, a mainland billing address, and WeChat Pay/Alipay/UnionPay-Visa. ⚠ We carry the body, not the headline — the first note is titled “OpenRouter really has banned Chinese IPs” but its body describes no IP ban and hedges the cause. 小红书 · 查饵丝-开发版 · 2026-04-17 · read end to end 2026-08-17 · 小红书 · 小鱼儿 · 2026-07-13 · read end to end 2026-08-17
- The card’s central number has one unjustified input, and independent deployments bracket it 10× apart. The vendor’s crossover is simply infra ÷ 0.055 — so everything rests on its unexplained “$200/month of infra”. Two first-hand, dated, itemised Japanese deployments straddle it. Minimal: “結論:推奨構成(月額 ¥3,000〜6,000)” — recommended configuration ¥3,000–6,000/month for LiteLLM on one 4 vCPU/8 GB Tokyo VPS (2026-04-02). Production-shaped: “常時稼働コストは、Guidance の README にある見積もりで月 $378 です” — the always-on cost is $378/month per the README estimate, itemised across six lines — ECS ~$115, multi-AZ RDS ~$98, NAT ~$50, Redis ~$25, ALB ~$25 and Route 53/CloudWatch/WAF/Secrets Manager ~$65, which is the $378 (2026-07-23). Through the vendor’s own formula: ~$340–690/month and ~$6,900/month. ⚠ The $378 is that repository’s README estimate, not a settled bill — the author says so. It is still better sourced than the “$200”, which the vendor page states with no derivation anywhere on it — and which, across 21 posts swept for this card — 12 Japanese, 9 Chinese, method: bodies pulled from the Zenn, Qiita, note.com and 掘金 APIs plus a reader proxy, limit: comment threads were not read and 知乎 search stayed CAPTCHA-walled, nothing independently reproduces. Zenn · yosh1 · published 2026-04-02 · body read 2026-08-17 via the Zenn API · Zenn · hikotty · published 2026-07-23 · 13 likes · body read 2026-08-17 · formula from openrouter.ai · 2026-06-19 ⚠ VENDOR — same page as the crossover item in the dropdown, cited twice on purpose: once for what it concedes (the arithmetic runs against its own interest) and once for what it assumes (the $200 input)
- The first-hand account that landed on the self-hosted side, and the operational reason why. After a provider outage: “We called the API directly from six different services. So "just switch to another model" meant editing six codebases, opening six PRs, and shipping six deploys. During the incident.” He priced both shapes — “Managed (OpenRouter, Cloudflare AI Gateway, Portkey)… The catch is your traffic and sometimes your prompts go through a third party” against “Self-hosted (LiteLLM): you run the proxy, keys stay on your infra… This is what I landed on.” And the thing he did not expect to matter: “cost visibility… That turned out to sell it internally way more than the failover did.” He also states the case against himself: “the gateway is another thing that can go down, a managed one adds a bit of latency and a bill, and if you only call one model from one service it’s probably overkill.” reddit.com · r/DeepSeek · u/Particular-Room8732 · 2026-08-14 · read at its own URL through agent-reach 2026-08-17 · outside the frozen n=13 roster (see coverage) — quoted here, not counted in the bar
- A named company publicly reported downstream compromise — the card had no named victim at all. “Mercor says it was hit by cyberattack tied to compromise LiteLLM” (TechCrunch via HN 47596739, 2026-04-01, 151 points / 31 comments). From that thread, on the vendor’s response: “The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance”. And the person who found it went on the record two days after the incident: “Callum here, I was the developer that first discovered and reported the litellm vulnerability on Tuesday. I’m sharing the transcript of what it was li[ke]” (HN 47531967, 441 points). ⚠ Neither the TechCrunch article nor the transcript was fetched — headline and thread comments only, so this card describes no scope, no victim count and no impact. This evidence points against the self-hosted side, and omitting it was an omission in this card’s own favour. HN 47596739 · 2026-04-01 · 151 pts / 31 comments · read 2026-08-17 · HN 47531967 · 2026-03-26 · the discoverer’s own account — same thread as the counts item above, cited twice on purpose: once for its comment count, once for what its author says · ⚠ both cited at thread level — the linked articles were NOT read
Show all 27 sourcesShow fewer
- The vendor concedes the crossover against itself, which is why it is quotable: “Divide your monthly infrastructure cost by the 5.5% fee. At roughly $200/month of infra, LiteLLM gets cheaper once your model spend passes about $3,600/month; at $500/month of infra, that line moves to about $9,100/month.” The arithmetic checks: 200 ÷ 0.055 = 3,636; 500 ÷ 0.055 = 9,091. It also names when to pick the rival: “Pick LiteLLM when data can’t leave your network…” openrouter.ai/blog/insights/openrouter-vs-litellm · 2026-06-19 · read 2026-08-17 · ⚠ VENDOR comparing itself to its named rival — tied-lowest neutrality in the ledger (0.05)
- The switch-away case, stated by someone actually considering it: “Historically acquisitions have never really been good for customers. Time for me to look for an OpenRouter alternative? At least they’re also as easy to switch from as the model providers they proxy.” Note what he concedes in the same breath — the switching cost is low, which is also the reason not to pre-emptively move. HN 49324039 · skeledrew · 2026-08-16 · re-located at source 2026-08-17 · the sweep first reported this handle as “therealdrag0” — wrong, and corrected here
- What the fee actually buys, per the thread it was argued in: “the value of openrouter is it offers centralized billing… switching to a new model, or a new provider of the same model, doesn’t mean setting up a new billing account with a new provider” (notatoad). And against it: “I don’t understand the people who use… expensive models like Claude Opus with OpenRouter because that 5% surcharge is meaningful at that level of cost” (minimaxir). Both are true at different spend levels — which is the card’s point. HN 49323955 · notatoad · 2026-08-16 · HN 48338877 · minimaxir · 2026-05-30 · both re-located 2026-08-17; the sweep reported the second handle as “827a” — wrong, corrected
- The substitution is genuinely the live question, not our framing: “Isn’t this what LiteLLM is doing? And is Open Source? Maybe I am asking a dumb question because this is the age-old SaaS vs OSS debate, but I am struggling to find the angle here.” Asked inside the acquisition thread, unanswered there. HN 49326020 · murlax · 2026-08-17
- Machine-checkable — and one of its “contradictions” dissolved when we opened the file.
BerriAI/litellm: 56,438★ (repos.ecosyste.ms,last_synced_at2026-08-16; the mirror lags — itslast_synced_atis a day before this card), 10,617 forks, 4,903 open issues, 16,614 commits across 375 committers, anddefault_branchislitellm_internal_staging, notmain. Thelanguagefield saysPythonwhile the repository’s own description reads “Rust core with Python SDK” — consistent with the HN thread “LiteLLM Migrates to Rust” (id 48644899, 2026-06-23) and with Chinese coverage dated 2026-07-08. ⚠ The licence field — which this card once carried as an unresolved contradiction — turns out not to be a contradiction at all:other/NOASSERTION is what GitHub’s classifier returns when a carve-out preamble defeats exact-match detection, and ecosyste.ms simply mirrors GitHub. The file itself is unambiguous (see the licence row above). repos.ecosyste.ms · BerriAI/litellm ·last_synced_at2026-08-16T07:39:46.757Z · licence resolved against the LICENSE file itself · read 2026-08-17 · same figures independently checkable at api.github.com/repos/BerriAI/litellm — a verifier saw the ecosyste.ms endpoint return402under rate limiting; it returned200on re-check 2026-08-17 - The corpus most hostile to paid API middlemen exempts this class explicitly: “本文(及前文)的中转特指各种类型的廉价中转,不包括 openrouter / cloudflare ai gateway 之类的商业中转” — the ‘relays’ here mean cheap relays; they do NOT include commercial ones like openrouter. Two self-promoting relay sellers in that same thread were excluded and are named in
quotes.md. v2ex.com/t/1232923 · ImSingee · 2026-08-08 · cached render, replies as rendered only - The fee is a real cost people do the sums on, in a language the English corpus never checks. “CF 走的是 api key 的形式, 按照官网定价走, 然后多收你 5%的手续费… 没必要多花这 5%” (JoeJoeJoe). The OP of that thread also corrected himself in public: “是我描述错了,是手续费,不是费率” — I described it wrong, it is a handling fee, not a rate. v2ex.com/t/1229723 · JoeJoeJoe reply #5, 2026-07-25; Xiangliangliang Supplement 1, 2026-07-25 · cached render
- The price moved, and it IS reconciled — this card previously said it was not. The July ~$10B and the August $7B+ are the same quantity at two points in one negotiation, not two outlets disagreeing. TechCrunch chains them: “The Wall Street Journal reported last month that Stripe and OpenRouter were in acquisition talks. Now, Bloomberg said those discussions have led to a deal price of more than $7 billion.” And the CEO was asked on the record on 2026-08-10, six days before Bloomberg — “There are reports that you are selling to Stripe for $10 billion. Is that going to happen?” — and answered “I can’t… comment, but… Whatever happens, we’re… going to execute on the vision.” The separate $1.3B is a different measure entirely — the post-money on May’s $113M Series B (not $120M; Benzinga has that wrong). ⚠ Still open: whether the WSJ itself framed $10B as a valuation or a price — its page is unreachable and downstream paraphrases split, so this card puts no label in WSJ’s mouth. techcrunch.com · 2026-08-16 · body read 2026-08-17 · 20VC · Alex Atallah · published 2026-08-10 · 00:58:56 ⚠ auto-generated captions (ASR) · openrouter.ai/announcements · $113M Series B, 2026-05-28
- A prior, separate LiteLLM security finding — do not conflate it with the supply-chain incident. “Breaking LiteLLM: From Low-Privilege User to Admin and RCE”, HN id 48498028, 4 points, 2026-06-11. Different date, different class of bug, and published by a security vendor with a commercial interest in the finding. obsidiansecurity.com · via HN 48498028 · 2026-06-11 · ⚠ SECURITY VENDOR — logged, not used as a verdict · ⚠ THE ARTICLE ITSELF WAS NOT FETCHED — this is a title-level citation, known via the HN story record; nothing is attributed to its contents
- One story, four simultaneous headlines — and the slug is the least reliable of them. Bloomberg’s URL slug on both domains says
nears-deal; bloomberg.com’s indexed<title>says “Finalizes”; the Bloomberg Law page as actually rendered says “Stripe Clinches Over $7 Billion Deal”; and Benzinga, more than fourteen hours later, still says “Nears”. That is one story revised mid-cycle with the first framing fossilised in the URL — not outlets disagreeing. This card previously cited the slug as if it were evidence of “nears”. It is not. The body is the thing that matters, and it holds both halves at once: “has finalized an agreement… according to people familiar with the matter” and “The final price for the acquisition could change.” news.bloomberglaw.com · 2026-08-16 8:08 PM UTC · read 2026-08-17, paywall cuts mid-sentence · complete graf via Fortune’s Bloomberg syndication - A cost channel the 5.5% framing does not capture, first-hand. “4月2号出的 Qwen3.6Plus 在 Openrouter 上虽然输入输出免费,但是仍然可以产生工具调用等其他费用!…几个pdf下去直接十几刀没了” — a model that is free for input and output on OpenRouter can still generate other charges such as tool calls; the OCR path on a few PDFs cost ten-odd dollars. The crossover is computed on the 5.5%; this is money the 5.5% never sees. 小红书 · 栗卷卷卷_ · 2026-04-06 · 37 likes / 40 collects / 28 comments · read end to end 2026-08-17
- The Chinese-language corpus independently dated this incident to late March — and it exposes a 13-minute hole in the timeline. Fourteen 小红书 notes carry it dated 2026-03-25/26/27, which is the card’s central re-dating confirmed by a corpus that never read this card. The most detailed (2026-03-27) says “事情从 10:52 UTC 开始…v1.82.8 版本被人上传到了 PyPI” — but the vendor’s postmortem says 10:39 UTC. Most likely two packages with two upload times; we could not verify that, so this card asserts no single upload instant. The same account independently corroborates the vendor’s most self-serving claim — “这个版本根本不在 GitHub 上——没有对应的提交,没有 release tag”. And on scope: “不需要import,安装就中招” — installation alone is enough; no import required. 小红书 · 古法编程手艺人 · 2026-03-27 · read end to end 2026-08-17 · 小红书 · 硅谷阿羊 · 2026-03-25 · 127 likes · ⚠ root cause NOT stated: issue #24518 contradicts itself (“trivvy security scan dependency” vs a hijacked maintainer PyPI account)
- A solo operator who runs both, and turns data residency into a routing property — this card’s verdict reached independently in a language it had never read. “client-* のルートは…OpenRouterのような、多数のモデルを束ねる「breadth系」の経路にはそもそも解決先が存在しない” — the client-* routes are wired only to direct provider APIs or local Ollama; for breadth-type paths like OpenRouter no resolution target exists in the first place — so “設定の書き間違いで顧客データがOpenRouterへ飛ぶ、という事故の形がなくなります。” — the accident-shape where a config typo sends customer data to OpenRouter ceases to exist. ⚠ He scopes himself honestly: “この基盤を動かし始めてまだ1ヶ月ほどです” — about one month, not a year — and withholds the config because it carries client data, so it is not independently reproducible. Zenn · seiryu_dev · published 2026-07-16 · body read 2026-08-17 · no stake disclosed or detected
- The 5.5% fee is invisible in Japanese, and actively misdescribed in Chinese relay marketing. Across ~80 Zenn/Qiita/note titles and 10 full Japanese bodies — including cost-motivated posts by authors who had topped up OpenRouter credit — the fee is mentioned zero times. In Chinese it appears twice, and both times from a party with a stake: Alibaba’s own gateway team, comparing OpenRouter to its Higress product, corroborates both prongs — “收取 5.5% 过路费(支持加密货币,过路费 5%)” and “使用自己的 API Key(BYOK),OpenRouter 加收 5% 过路费” — ⚠ that BYOK line is STALE and is NOT the live term. It is a 2025-07-31 post by a competitor; OpenRouter’s own docs as of 2026-08-17 make BYOK free below a $25,000/month allowance, 5% only above it. Cite this source for the 5.5% credit-purchase fee, never for BYOK. ⚠ And one Zhihu piece is flatly wrong AND is affiliate marketing: “因为OpenRouter会在官方价格上加一层自己的利润” — because OpenRouter adds its own profit on top of the official price — which contradicts the documented 0% markup. Every mention of the product it sells is a tracked link. So Chinese-language “OpenRouter is expensive” sentiment is contaminated and is weighted down here unless the author shows workings. 掘金 · 阿里云云原生 · 2025-07-31 · read 2026-08-17 ⚠ ALIBABA’S OWN GATEWAY PRODUCT — a direct competitor, cited for the fee only · 知乎 · read 2026-08-17 ⚠ AFFILIATE MARKETING, and factually wrong — logged as a contaminant, never as evidence
- The posture the biggest thread actually produced, with its own hedge intact. In HN 47501426 (938 points / 496 comments, the day of the compromise): “pretty horrifying. I only use it as lightweight wrapper and will most likely move away from it entirely. Not worth the risk” (bfeynman). ⚠ That is a stated intention on the day of an incident, not a completed switch, and this card does not count it as one. From the same thread, on the vendor’s own issue tracker: “What is happening in this issue thread? Why are there 100+ satisfied slop comments?” (iwhalen). HN 47501426 · 2026-03-24 · read 2026-08-17 — same thread as the counts item, cited twice on purpose: once for its 938/496 counts, once for a posture inside it · outside the frozen n=13 roster — quoted, not counted in the bar
- The concession from the one source with every reason to say the opposite. A Japanese developer who quit LiteLLM for a single-binary Go tool of his own making — his title is “LiteLLMをやめて…”, having quit LiteLLM — nonetheless writes: “数百人の開発者が叩く社内LLMゲートウェイを構築するなら、運用実績の長いLiteLLMが圧倒的に有利です”, if you are building an in-house LLM gateway hit by hundreds of developers, LiteLLM, with its long operational track record, is overwhelmingly advantageous. And on running both: “両方を併用するパターンも有効で、社内中央プロキシをLiteLLMで運用し、開発者ローカルだけgo-llm-agentから直接プロバイダーへ抜ける、という構成も問題なく機能します” — using both together is also valid: running the central in-house proxy on LiteLLM while only developer-local traffic goes straight out to providers. ⚠ His “both” pairs LiteLLM with his OWN Go tool, not with OpenRouter — his article does not mention OpenRouter at all (0 occurrences against 15 of his own tool). So the citable part is the concession he makes against his own argument, not his recommendation.
Zenn · okamyuji · published 2026-05-29 · 43 likes — the highest-engagement Japanese LiteLLM article found · body read 2026-08-17 via the Zenn API · ⚠ DISCLOSED STAKE — he is showcasing his own competing OSS (
go-llm-agent, MIT), so this item carries his concession and never his recommendation
Why confidence is LOW
Coverage — what we read, what we skipped
⚠ THIS CARD WAS SWEPT TWICE, AND THE FIRST SWEEP HAD NO agent-reach. The scheduled cloud builder that drafted it could not call mcp__agent-reach__* at all — verbatim, No matching deferred tools found — with WebFetch returning {"error_type":"PROVENANCE_REQUIRED"} and Reddit 403, so the draft rested on HN + V2EX only. It was re-swept on 2026-08-17 from a machine where agent-reach works, and that second sweep falsified five claims the draft carried: the BYOK terms (“first 1M requests/month waived” — the allowance is a dollar figure and the docs say explicitly “not request count”), the licence (recorded as unknowable; the file reads clean), “optional Redis” (LiteLLM’s own docs say required past one instance), the claim that no source reconciled $10B with $7B+ (TechCrunch reconciles them in one sentence), and the Bloomberg slug cited as evidence of “nears” (the page as rendered says “Clinches”). Those corrections are the main thing that changed; the verdict did not.
READ — PRIMARY AND MACHINE-CHECKABLE: BerriAI’s own postmortem; GitHub advisory GHSA-5mg7-485q-xm76; all 12 of BerriAI/litellm’s 2026 security advisories via api.github.com (HTTP 200 — it did not 403 from this machine, unlike the cloud run); incident issue #24518; the root LICENSE and enterprise/LICENSE.md (via gh api; raw.githubusercontent.com returned 429: Too Many Requests, a workaround rather than a gap); repos.ecosyste.ms; LiteLLM’s own deploy/prod/quickstart docs; OpenRouter’s pricing page, docs FAQ, 2025-06-09 fee post and 2026-06-19 comparison; and openrouter.ai/announcements plus stripe.com/newsroom, both read 2026-08-17 to establish that neither company has posted about the deal. Johann Rehberger’s research was read at the primary after the draft cited it second-hand through an X post behind a t.co link — and the primary is materially weaker than the relay implied. ENGLISH FORUMS: HN threads are each cited with their own count and never summed; eight comments were re-fetched at their own permalinks. ⚠ The original sweep cited 9 threads on Hacker News — six from the August acquisition window and three from June — with March missing from all 9, so it missed the news cycle the story actually broke in, including the 938-point / 496-comment thread that is the most-discussed LiteLLM story on HN. Those threads were added on 2026-08-17 after a verifier ran the endpoint this card already cited and found them in its top four. The lesson is recorded rather than smoothed over: a sweep anchored on one news window will miss the window the story actually broke in. 中文: three V2EX threads (cached Exa render — reply lists are as rendered, view counts are the snapshot’s, so not a full-thread read; the one quoted sentence was re-read live at v2ex.com on 2026-08-17 to settle a splice); six 小红书 notes read end to end on signed URLs — note the limit: that is the note body in each case, not the comment threads under them (one carries 108 comments, none of which were read) (the draft had read two and logged four as titles); all four B站 items now carry a publish date, view/like/favourite/reply counts and the uploader-written description — we cite only the title, the uploader-written description and the counts from all four, and quote no spoken content from any of them — this project’s standing rule for B站, applied here as a self-imposed limit rather than a finding: we did not query a subtitle endpoint for these four and make no claim about what one would return. ALSO: a 20VC interview in which OpenRouter’s CEO is asked about the $10B on the record and declines to answer — auto-generated captions (ASR), flagged as such wherever used.
NOT REACHED — TRIED, FAILED, ERROR QUOTED: The Wall Street Journal, the primary behind the entire July $10B figure, failed on three routes: WebFetch Claude Code is unable to fetch from www.wsj.com; Jina Reader Warning: This page maybe requiring CAPTCHA, please make sure you are authorized to access this page.; archive.ph Warning: Target URL returned error 429: Too Many Requests. bloomberg.com itself: The server returned HTTP 403 Forbidden. (Bloomberg Law carries the same story and did load, paywall-cut mid-sentence; Fortune’s syndication supplied the missing paragraph.) X — PARTLY read, and the earlier wording here was wrong. Two X posts were read at their own URLs through agent-reach on 2026-08-17 and are quoted in the receipts; what failed was the profile page x.com/OpenRouter, The server returned HTTP 402 Payment Required. So X is a partial gap — no profile-level sweep — not an unreached platform. Reddit — and this footer previously misdescribed it. The scheduled cloud builder failed on Reddit entirely (httpStatusCode 403, tag SOURCE_NOT_AVAILABLE seven times; No active connection found for toolkit(s) 'reddit' in this session.), and the ~18 handles reachable only through an unverifiable third-party mirror were all excluded and remain excluded. But two Reddit threads WERE later read at their own URLs through agent-reach on 2026-08-17, and one of them is a first-hand operator who chose the self-hosted side — he is quoted on this card. He is outside the frozen n=13 roster under the same rule applied to the Japanese operators, not because he was unreachable. Saying otherwise would have quietly tilted the bar toward the managed router. 日本語 AND THE CHINESE DEV BLOGS — THE DRAFT’S BIGGEST GAP, NOW CLOSED. The first sweep reached Japanese articles but could retrieve titles only, so Japanese contributed zero voices. That was a tooling failure, not an empty corpus. Zenn and Qiita both expose article APIs that return the full body with an exact publication timestamp; 掘金 enumerates through its search API with bodies via a reader proxy — the draft’s “Please wait...” shell was a direct-fetch artefact only; and note.com returns full JSON once a User-Agent header is sent, which is almost certainly what blocked the earlier attempt. 21 full dated bodies were read this way — 12 Japanese (8 Zenn, 2 Qiita, 2 note.com) and 9 Chinese (5 掘金, 3 知乎, 1 博客园), and they produced the single most important finding of the re-sweep: two independent itemised infrastructure figures that bracket the vendor’s crossover assumption about tenfold. 知乎 is a PARTIAL gap, not a blanket one: its search endpoint is CAPTCHA-walled — HTTP/2 403, then via a reader proxy Title: 安全验证 - 知乎 and Warning: This page maybe requiring CAPTCHA, please make sure you are authorized to access this page. — and the CAPTCHA was deliberately not attempted, because defeating bot-detection is out of bounds for this project; individual 知乎 column articles read fine about half the time, and the failures were one 403: Forbidden, one removed article and one login wall. CSDN is paywalled: 最低0.47元/天 解锁文章, intro only. What the Japanese corpus did NOT contain is as useful as what it did: across ~80 Zenn/Qiita/note titles and 10 full Japanese bodies, the 5.5% platform fee is mentioned zero times — including by authors who had topped up OpenRouter credit — so this card does not claim the fee is common knowledge. Excluded and named: an SEO comparison cross-posted verbatim to two platforms (one source, not two), roughly ten machine-generated near-identical Qiita posts, a Zenn piece that is a self-declared translation of a Reddit post, and a note.com analysis whose author sells a competing router. One follow-up is named and not carried: a Japanese company’s engineering blog on AI token-cost governance (2026-08-09) was found title-only and its body was not read. DELIBERATELY NOT FETCHED, and named so the omission is visible: Sonatype’s analysis of the PyPI compromise, Obsidian Security’s privilege-escalation write-up, issue #24512, the two walkthrough videos embedded in the Rehberger post. CISA’s KEV catalogue WAS fetched (catalogVersion 2026.08.17) after a verifier pointed out that a one-request public JSON was changing a number on the card face: it holds two LiteLLM entries where the card had said one, and the card now states two as our own finding rather than as a researcher’s claim.
WATCH OUT — WHAT THIS CARD STILL DOES NOT KNOW: The roster is two platforms, not eight. n=13 is HN and V2EX only and was deliberately not re-cut by the second sweep — it is an under-claimed subset, never a saturation census. The two 小红书 notes that appear to corroborate the $3,600 crossover were refused as independent voices: both are dated within five days after OpenRouter’s own comparison page — and they are refused on different strengths of evidence: one lands on the vendor’s rounded $3,600 artefact and drops the $200 premise the figure depends on, while the other carries zero arithmetic and is refused only for reproducing the same axes days later, which is weaker and is stated as weaker — counting them would have put the vendor’s number on this card wearing a third-party badge. The 2026-03 Chinese security corpus is cited as a dated cluster of 14 notes, never as 14 voices — it is one news event summarised many times. The B站 corpus around LiteLLM is substantially replacement marketing (titles promising 「比 LiteLLM 快 50 倍」 and 「快 14.5 倍」 — 50× and 14.5× faster than LiteLLM), and every such figure is treated as an unmethodologised uploader assertion and kept off the card face. An unresolved 13-minute hole sits in the incident timeline — the vendor says the packages went live at 10:39 UTC, an independent write-up says v1.82.8 was uploaded at 10:52 — so this card asserts no single upload instant. This card also states no root cause for the compromise, because the incident issue contradicts itself between its maintainer block and its own summary, and the analysis that might settle it was not fetched. Counts drift within a single day — HN 49323381 read 301/199, then 328/205, then 332/205 across three passes on 2026-08-17 — so every count here is as read, never a fact about the thread. Press scale figures are quoted only as thread titles, never asserted as findings. The underlying figures: 2,488 organisations, 153GB and 434,000 pipelines were seen at headline level only, and the two outlets’ user/model counts disagree with each other. Nothing anywhere states what happens to OpenRouter’s product, API or pricing after the reported acquisition — that was checked across five stories, and this card therefore makes no claim about it. ⚠ The 小红书 links on this card will not open for you. Those notes are reachable only through signed URLs whose tokens expire; the durable key is the note id plus author plus a verbatim substring, all of which are in the receipts, and the bare links are retained so the id is visible. This is a property of the platform, not a paywall. ⚠ Only 64 of the 117 ledger rows carry a date field — the other 53 are almost all rows the original scheduled builder wrote without one, and dates were never invented to fill them. Every source cited on the card face carries a publication date, a read date, or both in its own citation line; but the ledger behind it is only about half dated, and a reader auditing all 117 rows will see that. Confidence is LOW, and that is the honest level for a card whose central commercial fact is a deal neither party will confirm.
Show every source we read (117) Hide the ledger
The 117 sources in this card's ledger — 49 of them quoted above. Sources we read and did not quote are listed too, with why. This is the ledger, not a claim of exhaustiveness: anything the sweep read but deliberately left out of it is named in the coverage note above, with the reason. Reliability and neutrality are our own scores, not the publisher's. Vendor-owned pages are marked in the notes and never carry the verdict.
- vendor docs — docs.litellm.ai/blog/security-update-march-2026 “Security Update: Suspected Supply Chain Incident”. VENDOR (subject B) describing its own incident. Unusually specific and self-limiting (names the 40-minute window, says Docker path unaffected). Reliability high because specific+dated+falsifiable; neutrality near-floor because it is the affected party. Facts used; verdict never.
- github — github.com/advisories/GHSA-5mg7-485q-xm76 “Two LiteLLM versions published containing credential harvesting malware”. Independent of BerriAI. Confirms dates, range, CWE-506, and states 'No known CVE'. The strongest single artefact in this ledger.
- vendor blog — openrouter.ai/blog/announcements/simplifying-our-platform-fee/ “Simplifying Our Platform Fee”. VENDOR (subject A) on its own pricing = authoritative for the fact, worthless for the verdict. CRITICAL: dated 2025-06-09, a year older than the coverage that treats it as news.
- vendor blog — openrouter.ai/blog/insights/openrouter-vs-litellm/ “OpenRouter vs LiteLLM: Managed vs Self-Hosted Gateway”. VENDOR comparing itself to its named rival - lowest neutrality in the ledger. Quotable only because its crossover arithmetic concedes against itself and checks out (200/0.055=3636). Never the verdict.
- GitHub metadata (ecosyste.ms) — repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BerriAI%2Flitellm “BerriAI/litellm repository metadata”. Used in place of api.github.com, which 403s this sandbox. Every figure carries last_synced_at 2026-08-16T07:39:46.757Z - it is a mirror, so it lags.
- Hacker News (algolia) — hn.algolia.com/api/v1/search?query=openrouter&tags=story “HN story search: openrouter”. One entry per thread. Counts drift within the day; recorded with updated_at.
- Hacker News (algolia) — hn.algolia.com/api/v1/search?query=litellm&tags=story "HN story search: litellm". ⚠⚠ THIS ROW PREVIOUSLY READ "Confirms the breach thread at 6 points / 0 comments - the asymmetry finding". THAT WAS FALSE AND THIS ENDPOINT DISPROVES IT. Re-run 2026-08-17: nbHits 475, and the top hits are the MARCH threads — 47501426 (938 pts / 496 comments, 2026-03-24), 47501729 (739 pts / 1 comment, merged by a moderator into 47501426), 47531967 (441/147, the discoverer's own account), 47596739 (151/31, Mercor named as a downstream victim). The compromise is the most-discussed LiteLLM story in HN history. The 6-point/0-comment thread (49279862, 2026-08-12) is an AUGUST FOLLOW-UP. One entry per thread, never summed. See quotes.md §29.
- Hacker News — news.ycombinator.com/item?id=49326735 “HN comment - jdgoesmarching”. Re-located at source. Priced the decision over a year and chose managed. Repeats the 'just has a major vulnerability' timing error - quoted with the correction attached.
- Hacker News — news.ycombinator.com/item?id=49324039 “HN comment - skeledrew”. Re-located. Sweeper misattributed this to 'therealdrag0'.
- Hacker News — news.ycombinator.com/item?id=49326020 “HN comment - murlax”. Re-located. Names LiteLLM as the OSS equivalent - shows the substitution is the live question.
- Hacker News — news.ycombinator.com/item?id=49323955 “HN comment - notatoad”. Re-located. Best statement of what the fee actually buys: centralized billing.
- Hacker News — news.ycombinator.com/item?id=48341517 “HN comment - 542458”. Re-located. 'worth the 5% to me'.
- Hacker News — news.ycombinator.com/item?id=48338877 “HN comment - minimaxir”. Re-located. Sweeper misattributed this to '827a'. States the fee bites at high spend.
- Hacker News — news.ycombinator.com/item?id=48340341 “HN comment - antonkochubey”. Re-located. Markup-context argument.
- Hacker News — news.ycombinator.com/item?id=48339935 “HN comment - dmurray”. Re-located.
- v2ex (CN) — www.v2ex.com/t/1231697 “我为什么放弃低价 AI API 中转,自己做了一套 OpenRouter Gateway”. Best independent source of the sweep. First-hand, methodologically careful, explicitly refuses to over-claim model substitution. Read from a CACHED Exa snapshot - the 985-view count is the snapshot's, and the render is not a full-thread read.
- v2ex (CN) — www.v2ex.com/t/1229723 “中转站要废了”. Corroborates OpenRouter 5.5% from an unrelated angle; OP posts his own correction (手续费 not 费率). Cached render.
- v2ex (CN) — www.v2ex.com/t/1232923 “真的不建议任何人用中转 2”. Explicitly carves OpenRouter out of the cheap-relay criticism. Thread also contains two self-promoting relay sellers, both excluded and named. Cached render.
- techcrunch.com — techcrunch.com/2026/08/16/stripe-will-reportedly-acquire-ai-gateway-startup-openrouter-for-7b/ “Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+”, by Anthony Ha, 2026-08-16 1:57 PM PDT. BODY NOW READ IN FULL 2026-08-17 (was headline-only). Carries the sentence that RECONCILES the two prices: “The Wall Street Journal reported last month that Stripe and OpenRouter were in acquisition talks. Now, Bloomberg said those discussions have led to a deal price of more than $7 billion.” Also confirms $113M Series B at a reported $1.3B valuation, and Stripe’s “does not comment on rumors or speculation”.
- news.bloomberglaw.com — news.bloomberglaw.com/mergers-and-acquisitions/stripe-nears-deal-to-buy-ai-firm-openrouter-for-over-7-billion Bloomberg, 2026-08-16 8:08 PM UTC. NOW READ (paywall cuts mid-sentence at “as the information is”; Fortune’s syndication carries the graf complete). ⚠ FOUR renderings of ONE story: URL slug “nears-deal”, bloomberg.com <title> “Finalizes”, the bloomberglaw page AS RENDERED “Stripe Clinches Over $7 Billion Deal to Buy AI Firm OpenRouter”, Benzinga 12h later still “Nears”. One story revised mid-cycle. DO NOT cite the slug as evidence of “nears”. Key: “has finalized an agreement… according to people familiar with the matter” AND “The final price for the acquisition could change.” in the same story; “OpenRouter declined to comment.”
- www.wsj.com — www.wsj.com/tech/ai/stripe-in-talks-to-buy-buzzy-ai-model-marketplace-openrouter-decc6a74 Source of the ~$10B July figure. STILL UNREACHABLE after three routes on 2026-08-17, errors quoted: WebFetch → “Claude Code is unable to fetch from www.wsj.com”; Jina Reader → “Warning: This page maybe requiring CAPTCHA, please make sure you are authorized to access this page.”; archive.ph → “Warning: Target URL returned error 429: Too Many Requests”. ⚠ Downstream paraphrases SPLIT on whether WSJ said “valuation” or “price” — the card must not put a label in WSJ’s mouth.
- siliconangle.com — siliconangle.com/2026/08/16/stripe-reportedly-finalizes-deal-buy-ai-model-router-openrouter-7b/ “Stripe reportedly finalizes deal to buy AI model router OpenRouter for more than $7B”. Headline only. Aggregator-tier.
- fortune.com — fortune.com/2026/08/16/stripe-7-billion-deal-ai-firm-openrouter-acquisition/ “Stripe clinches over $7 billion deal to buy AI firm OpenRouter”. Headline only.
- finance.yahoo.com — finance.yahoo.com/technology/ai/articles/stripe-talks-acquire-openrouter-potential-215104525.html “Stripe in talks to acquire OpenRouter in potential $10 billion deal, WSJ reports”. A rewrite citing WSJ. Used only to evidence that the $10B figure was reported, not as an independent report.
- gigazine.net — gigazine.net/news/20260817-stripe-acquire-openrouter-7-billion/ “1.1兆円超でStripeがAIゲートウェイサービスのOpenRouterを買収か”. JP framing of the same Bloomberg story (¥1.1tn). Retrieved via WebFetch's SUMMARISING model, so the headline wording is not certainly verbatim. Not on the card face.
- www.securityweek.com — www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/ “Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack”. Title-level only. The '2,500+' figure is NOT traced to primary and does not appear on the card face.
- www.helpnetsecurity.com — www.helpnetsecurity.com/2026/08/13/litellm-breach-stolen-credentials-leak/ “153GB of stolen credentials surface after LiteLLM supply chain attack”. Title-level only. 153GB not traced to primary. Not on card face.
- www.techtimes.com — www.techtimes.com/articles/324451/20260814/litellm-supply-chain-hack-hit-2488-firms-stolen-keys-still-work-five-months.htm “LiteLLM Supply Chain Hack Hit 2,488 Firms; Stolen Keys Still Work Five Months On”. The sole origin of the 'keys still work' claim in this ledger. Title-level only, low-tier outlet. NOT on the card face - it is exactly the kind of headline that becomes a laundered verdict (bug #39's shape).
- cybernews.com — cybernews.com/security/litellm-supply-chain-attack-credentials-leak/ “Gargantuan trove of stolen secrets surfaces from LiteLLM supply chain attack”. Title-level only.
- hackread.com — hackread.com/litellm-breach-2500-companies-434k-ci-cd-pipelines/ “LiteLLM Breach Linked to 2,500+ Companies and 434K CI/CD Pipelines”. Title-level only. Source of the 434,000-pipeline figure; untraced.
- cyberinsider.com — cyberinsider.com/litellm-breach-data-shows-supply-chain-attack-impacted-2488-firms/ “LiteLLM breach data shows supply chain attack impacted 2,488 firms”. Title-level only.
- security vendor — www.tenable.com/plugins/nessus/304806 “LiteLLM 1.82.7 / 1.82.8 Supply Chain Compromise (GHSA-5mg7-485q-xm76)”. Used ONLY to record the CVE discrepancy: Tenable attributes CVE-2026-33634 where GitHub says 'No known CVE'. Security vendor - commercial interest in the finding.
- www.bitsight.com — www.bitsight.com/blog/litellm-versions-1-82-7-1-82-8-supply-chain-compromise “LiteLLM versions 1.82.7/1.82.8 supply chain compromise”. Security vendor. Source of the 'TeamPCP' attribution, which we do not assert.
- www.obsidiansecurity.com — www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce “Breaking LiteLLM: From Low-Privilege User to Admin and RCE”. Security vendor. Prior, SEPARATE 2026-06 finding - must not be conflated with the March supply-chain incident.
- reddit.sentinel-team.org — reddit.sentinel-team.org/ “Reddit Sentiment Analyzer (third-party Reddit mirror)”. DISCOUNTED TO ZERO USE. Every Reddit quote this sweep obtained came from here because reddit.com returned 403 to every tool. Fidelity unverifiable against the live site, so all ~18 handles are excluded from n and from the card face - including two that would have HELPED the card.
- foresightnews.pro — foresightnews.pro/article/detail/99255 “对话 Jordan:Stripe 为什么花 100 亿买 OpenRouter”. Interviewee is co-founder/CEO of AIsa, a competing AI-agent marketplace - NOT an OpenRouter insider (the candidate list implied otherwise). Confirms the 100亿/$10B figure. Its fee-split claim (~2.9 of ~5 points to Stripe) is single-sourced and NOT on the card face.
- zhuanlan.zhihu.com — zhuanlan.zhihu.com/p/2019971751178694668 “开发者注意!Litellm遭遇供应链攻击 火绒已可全面拦截”. Antivirus vendor advertising its own detection. Useful only as INDEPENDENT CORROBORATION OF THE MARCH DATE (published 2026-03-25). Not a voice.
- segmentfault.com — segmentfault.com/a/1190000048111947 “2026 年 7 个值得关注的 OpenRouter 替代方案”. 'Alternatives' listicle promoting ServBay throughout. Excluded.
- juejin.cn — juejin.cn/post/7604678037808660516 “OpenRouter 国内用不了?这 3 个替代方案更适合中国开发者”. Author promotes his own product Ofox.ai. Excluded.
- aicoding.juejin.cn — aicoding.juejin.cn/post/7496528481841938467 “OpenRouter可能没那么安全”. Independent and honest ('I have no substantive evidence'), but dated 2025-04-23 and about a different concern. Not used.
- mp.weixin.qq.com — mp.weixin.qq.com/s/YBTpbsKHmfFeICoN1VIwqA “领导怒骂:不如把你裁了换成 Token!”. Plugs the author's paid course codefather.cn. Its CISPA-paper claim (45.83% model-identity mismatch across 28 relays) is interesting and UNVERIFIED - not on the card face.
- developer.hatenastaff.com — developer.hatenastaff.com/entry/2026/05/14/173453 “社内にLiteLLM Proxy(OSS版)を導入して…”. Hatena Inc.'s own engineering blog on its own deployment. Real named org running LiteLLM Proxy in production, but a self-report, and only the TITLE was retrievable. Not counted.
- note.com — note.com/zephel01/n/neea82390f387 “LiteLLM Proxy 脆弱性ガチ検証 2026…(代替CodeRouterの紹介)”. Author maintains CodeRouter, a competing project, and the title itself advertises it. Excluded.
- zenn.dev — zenn.dev/okamyuji/articles/golang-litellm-alternative-single-binary “LiteLLMをやめて自作Goバイナリに置き換えたら一気に軽くなりました”. Would be a genuine first-hand 'left LiteLLM' voice, but ONLY THE TITLE was retrievable - no verbatim body, no date, no LGTM count. Not counted. HIGH-VALUE TARGET for the next sweep.
- qiita.com — qiita.com/moritalous/items/005a5a2fa3783ba5df54 “Bedrockが無敵になれるツール LiteLLM”. Title only, no body retrievable. Not counted.
- youtube.com — youtube.com/watch?v=E6LCyUYxYr8 “OmniRoute vs OpenRouter vs LiteLLM: Inside the Local AI Gateway”. Title foregrounds a competing product. Description/transcript unreadable, so sponsorship is UNCONFIRMED rather than cleared. Never a verdict source.
- enterpilot.io — enterpilot.io/blog/benchmarking-ai-gateways-gomodel-litellm-portkey-bifrost-june-2026/ “Benchmarking AI Gateways: GoModel vs. LiteLLM vs. Portkey vs. Bifrost”. Self-submitted to HN (4 pts). Benchmark authored by a party with a product in the comparison. Excluded.
- vendor pricing page — openrouter.ai/pricing OpenRouter live pricing page. NOW READ 2026-08-17 (was “NOT READ”). ⚠ The page carries NO publication or updated date anywhere in its markup — any date attached to it is the capture date. Confirms 5.5% on both paid tiers and BYOK allowances “$25,000 of list price inference / month with no fees, 5% fee after” (PAYG) and “$200,000…” (Enterprise). ⚠ Greps for “0.80”, “minimum fee” and “markup” across the full 258KB return ZERO matches — the $0.80 minimum and 5% crypto rate are NOT here; their live home is openrouter.ai/docs/faq. ⚠ Carries “Fee discounts available” on both paid tiers: 5.5% is a LIST rate.
- zhuanlan.zhihu.com — zhuanlan.zhihu.com/p/2047369908347057529 “起底 AI中转站:封号跑路,模型降智,倒卖用户数据”. UNREACHED. Verbatim: CRAWL_UNKNOWN_ERROR (HTTP 500), retry CRAWL_LIVECRAWL_TIMEOUT (HTTP 504). Highly on-topic. Gap, not a negative finding.
- juejin.cn — juejin.cn/post/7620631529115844646 “LiteLLM 供应链攻击深度复盘:一个 .pth 文件如何窃取你所有云凭证”. UNREACHED. Returned only the 30-character JS shell 'Please wait...\n\nPlease wait...' on two attempts. The most on-topic Chinese artefact found and we could not read it.
- reddit — www.reddit.com/ “Reddit (all target subreddits)”. UNREACHED. Composio REDDIT toolkit verbatim: 'No active connection found for toolkit(s) reddit in this session.' Direct fetches: httpStatusCode 403, tag SOURCE_NOT_AVAILABLE (7 attempts, 7 failures). WebSearch allowed_domains verbatim: 'The WebSearch proxy rejected the request (HTTP 400).'
- reddit — www.reddit.com/r/DeepSeek/comments/1ux7i25/psa_for_anyone_calling_an_llm_api_directly_from/ FIRST-HAND SWITCH REPORT and the single best new voice from the gap-fill. u/Particular-Room8732 called an LLM API directly from six services, hit a provider outage, and moved everything behind a gateway. Frames the decision exactly as this card does — “Managed (OpenRouter, Cloudflare AI Gateway, Portkey)… The catch is your traffic and sometimes your prompts go through a third party” vs “Self-hosted (LiteLLM): you run the proxy, keys stay on your infra” — and lands on LiteLLM. Score 0, 13 comments. NOT yet promoted to the card face.
- reddit — www.reddit.com/r/DeepSeek/comments/1ux7i25/psa_for_anyone_calling_an_llm_api_directly_from/ ⚠ STAKE, SELF-DISCLOSED, EXCLUDED FROM THE VOICE COUNT. u/Maleficent_Pair4920: “Founder of requesty.ai here so take this with the appropriate grain of salt, we are a managed option like OpenRouter/Portkey”. His substantive point is still the best counter to the OP and is kept for that reason: a gateway itself becomes a single point of failure, so “whatever you pick needs its own failover story, either multi-region for a managed gateway or running LiteLLM behind a load balancer with more than one instance”.
- reddit — www.reddit.com/r/DeepSeek/comments/1ux7i25/psa_for_anyone_calling_an_llm_api_directly_from/ u/russjr08 — a THIRD option neither tool covers: “I end up using llama-swap which allows advertising cloud models as well as part of its proxying.” Relevant because the card frames a two-way choice.
- reddit — www.reddit.com/r/hermesagent/comments/1ufrtsf/models_providers_plans_megathread_june_2026/ ⚠ COMPILATION — “Sourced from: 31+ r/hermesagent threads, 290+ community comments”. Under this project roster rule a 汇总 is a CITABLE SOURCE BUT NOT A VOICE (the 老K precedent on card #3), so it is excluded from n. Carries two community findings on the fee axis: “OpenRouter markup: same model costs 4-5x more through OR resellers”, and “I would avoid silent auto-routing for anything that mutates state.” Score 99, 43 comments.
- x — x.com/i/status/2089307483861110974 FIRST-HAND, and dated the same day as this card. “If you are running enough agents, I think a local LiteLLM router becomes almost necessary… Set a Fallback Policy so that if the Deepseek model throws a rate limit or token limit error (HTTP 429), the router seamlessly redirects the request to a designated backup model without crashing the agent.” Low engagement (0 likes, 198 views) — weight on content, not reach.
- x — x.com/i/status/2089287842564317648 ⚠ RELAY, NOT A VOICE — and now SUPERSEDED. It summarised Johann Rehberger’s LiteLLM research second-hand behind a t.co shortlink. THE PRIMARY HAS NOW BEEN READ (see source embracethered-llm-heist-2026-08-03). Reading the primary showed this relay OVERSTATED the finding: the author states “The routing change itself is not a vulnerability”. Retained only to record that the card no longer depends on it.
- x — x.com/i/status/2089319137998700616 ⚠ ANALYST COMMENTARY, NOT A VOICE. Useful only for the post-acquisition landscape: “LiteLLM is still the self-hosted standard, zero-markup, loved by DevOps teams.” Also asserts OpenRouter took 40 months to $10M ARR. UNVERIFIED — the account is promoting a competitor (OrcaRouter) in the same post, so treat every figure as advertising until checked at source.
- bilibili (CN) — www.bilibili.com/video/BV11s7v69EqV B站, uploader 程序员暮闲 — title translates as “New API vs LiteLLM: which should you choose?”, score 4,232. ⚠ EXISTENCE AND UPLOADER-WRITTEN TITLE ONLY. B站 has no subtitle track, so per this project rule spoken content is never cited; nobody has read its description or comments yet.
- bilibili (CN) — www.bilibili.com/video/BV1XbRtBBEkA B站, uploader laozibaqingdiao — “Apimart vs LiteLLM Proxy:自建网关还是托管聚合” (“self-hosted gateway or managed aggregation”), which is THIS CARD QUESTION stated in Chinese. Score only 60. ⚠ Title only, not watched.
- bilibili (CN) — www.bilibili.com/video/BV17n3b6rEcY B站, 程序员暮闲 — “告别 LiteLLM:比 LiteLLM 快 50 倍的高性能大模型网关 Bifrost” (“farewell LiteLLM”), score 2,974. A LEAVING-LiteLLM signal toward a third tool, and a performance claim (50x) that is a vendor/uploader assertion, not a measurement. ⚠ Title only.
- bilibili (CN) — www.bilibili.com/video/BV1QE756MEQa B站, 鱼跃于渊Bit — “AI网关工具LiteLLM从Python迁移至Rust”, score 1,491. If LiteLLM is being ported Python→Rust that bears on the operator-cost axis. ⚠ UNVERIFIED CLAIM IN A VIDEO TITLE — check against the repo before it influences anything.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/6a3b900e000000001603ea7a READ END TO END 2026-08-17 (single-page note, no pagination). TechMemo, “OpenRouter vs LiteLLM:真正差别不是功能”. 1 like / 8 collects / 0 comments — LOW ENGAGEMENT, and engagement is used as a signal nowhere on this card. INDEPENDENTLY CORROBORATES THE VERDICT FROM A DIFFERENT LANGUAGE CORPUS: “新项目、小团队、原型验证:先 OpenRouter。高消耗、强合规、内部平台能力成熟:再看 LiteLLM。” — new projects / small teams / prototyping: OpenRouter first; high spend, strong compliance, mature internal platform: then look at LiteLLM. ⚠ Signed URL — xsec_token expires. Durable key: note id 6a3b900e…, author TechMemo, substring 「真正差别不是功能」.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/6a389c9b000000001102e662 READ END TO END 2026-08-17. 遥遥领先, “OpenRouter还是LiteLLM?算清楚这笔账再选”. 6 likes / 3 collects / 1 comment. ⚠⚠ CARRIES A CROSSOVER FIGURE THAT CONTRADICTS THE CARD FACE: “当月支出超3600美元时,自托管更划算” — self-hosting wins above US$3,600/month, whereas this card’s switch_if cites OpenRouter’s own comparison at ~$200/month of infrastructure. THOSE ARE NOT THE SAME QUANTITY and one of them is being read wrong. A VERIFIER MUST RESOLVE THIS BEFORE PUBLICATION. Also asserts “前100万请求免费” (first 1M requests free) — UNVERIFIED, not checked against OpenRouter pricing, do not repeat it. Also independently lands on run-both: “两者可组合使用”. Durable key: note id 6a389c9b…, author 遥遥领先, substring 「算清楚这笔账再选」.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/6a77e90e000000002403d1b9 抽屉外, “从零凭证到云环境,LiteLLM被完全攻陷” (“from zero credentials to cloud environment, LiteLLM fully compromised”), 5 likes. ⚠ TITLE ONLY — NOT READ. Chinese-language coverage of the gateway-compromise class, 8 days before this card. Likely the same Rehberger research cited second-hand elsewhere in this ledger; if so it is a THIRD relay of a primary nobody has fetched.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69c3ef09000000001f007d1a york, “大模型网关LiteLLM被投毒,karpathy 分享” (“LiteLLM gateway poisoned, shared by Karpathy”), 3 likes. ⚠ TITLE ONLY — NOT READ. Dated 2026-03-25, one day after the PyPI incident this card correctly re-dates to 2026-03-24 — useful as independent confirmation of the DATE, which is the card’s key correction against its own briefing.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69e6efd3000000002103ac4a 哈喽比特, “我把 LiteLLM 的 VPS 部署流程压成了5分钟” (“I compressed LiteLLM VPS deployment to 5 minutes”), 3 likes. ⚠ TITLE ONLY — NOT READ. Bears directly on the OPERATOR-COST axis, which is half this card’s crossover argument. Worth reading before the verifier signs.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/6a7b3611000000003300e53a ndhukyer, “成立15个月,月入6.8万美金:这个开源AI网关怎么赚钱?”, 15 likes. ⚠ TITLE ONLY — NOT READ, and the revenue figure is UNVERIFIED. Logged because open-gateway monetisation bears on the durability of the self-hosted option.
- embracethered.com — embracethered.com/blog/posts/2026/hijacking-litellm-for-fun-and-profit/ ★ THE PRIMARY, READ IN FULL 2026-08-17 (HTTP 200, 32,526 bytes) — replaces the second-hand X citation. “LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection”, Johann Rehberger. Date confirmed 3 ways (og:article:published_time, visible byline, RSS pubDate). Exactly ONE LiteLLM post in the blog’s 230-post archive. ⚠ SCOPE LIMITS THE RELAY DROPPED: author states “The routing change itself is not a vulnerability”; assumes the attacker ALREADY holds LITELLM_MASTER_KEY (post-exploitation, not an entry point); “does not by itself bypass client-side tool authorization”; and “applies, in principle, to other AI gateway products” — NOT LiteLLM-specific. NO CVE, NO GHSA, NO affected version range. NOT the same event as the March PyPI compromise. No commercial stake disclosed or detected; the “Red Team Director at Electronic Arts” claim came from a search-result summary, NOT the site — unverified.
- github — api.github.com/repos/BerriAI/litellm/security-advisories ★ NEW AND MATERIAL — the card had NONE of this. HTTP 200 with 12 advisories (did NOT 403 from the operator’s Mac). 2026: 3 critical, 5 high, 2 medium, 2 low (re-counted live 2026-08-17 against the API; an earlier card face said 4/4 and was wrong), spanning 2026-04-03 → 2026-06-30. This is a steady advisory stream, not one isolated incident, and it is a real operator cost the crossover arithmetic ignores. Most recent 2026-06-30 — over a month BEFORE the embracethered post, confirming that research has no advisory.
- github — github.com/advisories/GHSA-v4p8-mg3p-g94g CVE-2026-42271, high, CVSS 3.1 = 8.8, CWE-77. “LiteLLM: Authenticated command execution via MCP stdio test endpoints”. Affected >= 1.74.2, < 1.83.7; first patched 1.83.7. Verbatim: “The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host.” ✅ CONFIRMED FIRST-HAND against CISA 2026-08-17 (catalogVersion 2026.08.17): this CVE IS in the KEV catalogue, dateAdded 2026-06-08 — and so is CVE-2026-42208, dateAdded 2026-05-08. The earlier note here said it was unconfirmed while the card printed a KEV number; that contradiction is closed. See the cisa-kev-catalog row and quotes.md §23. ⚠ Date discrepancy: repo endpoint published_at 2026-04-21T17:19:18Z vs global /advisories/ 2026-04-25T23:27:54Z (nvd 2026-05-08).
- github — github.com/BerriAI/litellm/issues/24518 “[Security]: litellm PyPI package (v1.82.7 + v1.82.8) compromised — full timeline and status”. createdAt 2026-03-24T13:48:06Z; OPEN as of 2026-08-17; opened by isfinne (Rui Hu) — NOT by the maintainers, though it carries a [LITELLM TEAM UPDATES] block. THE SOURCE for the version numbers and the 2026-03-24 date (the embracethered post gives only “In March 2026”). ⚠⚠ CONTRADICTS ITSELF ON ROOT CAUSE: maintainer block says “Compromise came from trivvy security scan dependency”; its own Summary says the attacker “gained access to the maintainer’s PyPI account.” THE CARD MUST STATE NO ROOT CAUSE. Also: exfil domain litellm.cloud registered 2026-03-23, hours before the packages.
- sonatype.com — www.sonatype.com/blog/compromised-litellm-pypi-package-delivers-multi-stage-credential-stealer DECLARED GAP — NOT FETCHED in this sweep. Would be needed before ANY root-cause claim about the PyPI compromise (see issue #24518, which contradicts itself). Security vendor: commercial interest in the finding.
- fortune.com — fortune.com/2026/08/16/stripe-7-billion-deal-ai-firm-openrouter-acquisition/ Bloomberg’s story carried COMPLETE where Bloomberg Law paywalls it. 2026-08-16 6:27 PM ET. Supplies the graf Bloomberg Law cuts: “The final price for the acquisition could change. The discussions were described by people who spoke on condition of anonymity as the information is not public.” And: “A spokesperson for Stripe said the firm doesn’t comment on rumors or speculation. OpenRouter declined to comment.”
- techflowpost.com — www.techflowpost.com/en-US/article/33294 Chinese-language outlet, EN edition. States the repricing outright — the sentence that settles the $10B vs $7B question: “In late July, The Wall Street Journal and Axios reported the negotiation price between the two parties was around $10 billion, three weeks later it settled at a bit over $7 billion, about 30% lower than the rumors.” Secondary analysis, not a primary; used only to establish that the two figures ARE reconciled in public, which the card previously denied.
- axios.com — www.axios.com/2026/07/24/stripe-openrouter-merger-ai-currency 2026-07-24 14:22 UTC, Lucinda Shen. WebFetch got HTTP 403; agent-reach loaded it clean — NOT a gap. “Payments company Stripe is in talks to acquire OpenRouter for around $10 billion, Wall Street Journal reported Thursday.” ⚠ Its “tokens become increasingly fungible with money” quote is from a Stripe Sessions 2026 announcement about payments strategy generally — it is NOT a Stripe comment on the acquisition and must not be repurposed as one.
- benzinga.com — www.benzinga.com/media/26/08/stripe-reportedly-nears-over-7-billion-deal-for-ai-startup-openrouter 2026-08-17 06:27 ET. WebFetch 403; agent-reach loaded it — not a gap. ⚠⚠ CONTAINS A FACT ERROR — DO NOT PROPAGATE: “$120 million Series B”. OpenRouter’s OWN blog and TechCrunch both say $113M. Also its scale figures (200T tokens/mo, 10M+ users, 80 providers, 500 models) conflict with TechCrunch’s (8M users, 400+ models) — both are OpenRouter’s own claims at different dates; attribute and date, never average. Still carries the “Nears” framing 12h after Bloomberg revised to “Clinches”.
- youtube — www.youtube.com/watch?v=K72oZoloA4M ★ THE CEO ON RECORD, SIX DAYS BEFORE BLOOMBERG. 20VC, published 2026-08-10, 68:25. At 00:58:56–00:59:23 Stebbings: “There are reports that you are selling to Stripe for $10 billion. Is that going to happen?” Atallah: “I can’t can’t comment, but… Whatever happens, we’re we’re going to execute on the vision.” ⚠ AUTO-GENERATED CAPTIONS (ASR) — the doubled words are ASR artefacts; flag as ASR wherever used. ⚠ The cold-open teaser renders “a valuation of over a billion and a half”, which does NOT match the $1.3B on record — teaser numbers unreliable; the 00:58:56 exchange is the citable one. Independently confirms the July $10B was understood as the price of SELLING the company. Subject-adjacent (the CEO): low neutrality on the verdict, high value as a non-denial.
- vendor blog — openrouter.ai/announcements ★ READ 2026-08-17: NO acquisition post exists. Most recent post is “Understand your AI usage: every agent, model, and request”, Aug 17 2026 — OpenRouter shipped a routine product post the MORNING AFTER Bloomberg said the deal was finalized, and said nothing about it. This is the best dated, re-verifiable evidence of “no official confirmation”. Also the authority for “OpenRouter Raises $113M Series B” (May 28, 2026) — and its own investor list does NOT name Sequoia, though TechCrunch and Benzinga do.
- vendor newsroom — stripe.com/newsroom/news READ 2026-08-17: the ONLY OpenRouter item is 2026-01-29, “Stripe powers OpenRouter’s global AI model access for millions of developers” — the pre-existing payments partnership. NO acquisition announcement. Together with openrouter-announcements-index this establishes silence on both sides.
- vendor docs — openrouter.ai/docs/faq ★ THE LIVE HOME of the $0.80 minimum and the 5% crypto rate (both ABSENT from the pricing page). Verbatim: “OpenRouter charges a 5.5% ($0.80 minimum) fee when you purchase credits… Crypto payments are charged a fee of 5%.” ⚠⚠ AND IT FALSIFIES THE DRAFT CARD: “BYOK has a plan-dependent free allowance measured by LIST-PRICE INFERENCE COST, NOT REQUEST COUNT. Pay-as-you-go includes [$25,000] per month with no BYOK fee, while Enterprise includes [$200,000].” The draft’s “first 1M requests/month waived” is FALSE.
- github — github.com/BerriAI/litellm/blob/main/LICENSE ★ CLOSES A FALSE GAP. Read via `gh api` 2026-08-17 (raw.githubusercontent.com returned “429: Too Many Requests” — a workaround, not a gap). Identical blob SHA 3bfef5bae9b48c334acf426d5b7f21bc1913aab9 on main AND on the real default branch litellm_internal_staging. Verbatim: “Portions of this software are licensed as follows: * All content that resides under the “enterprise/” directory… is licensed under the license defined in “enterprise/LICENSE”. * Content outside… is available under the MIT license as defined below.” then unmodified MIT, “Copyright (c) 2023 Berri AI”. ⇒ “LiteLLM is MIT-licensed” is FALSE as a bare statement AND “the licence is unknown” is ALSO false. The GitHub/ecosyste.ms “other”/NOASSERTION field is a DETECTION ARTEFACT — the carve-out preamble defeats exact-match classification.
- github — github.com/BerriAI/litellm/blob/main/enterprise/LICENSE.md The carve-out, read 2026-08-17. Verbatim: the Software “may only be used in production, if you… have agreed to… the BerriAI Subscription Terms of Service… or otherwise have a valid BerriAI Enterprise license for the correct number of user seats”, and “you may copy and modify the Software for development and testing purposes, without requiring a subscription.” LOAD-BEARING: the $3,600 crossover assumes the MIT half only, while enterprise/ holds SSO, RBAC and audit logs — what a team at that spend tends to need.
- vendor docs (LiteLLM) — docs.litellm.ai/docs/proxy/deploy ★ FALSIFIES THE CARD’S “optional Redis”. Component table verbatim: PostgreSQL — “Required for the proxy’s auth and tracking features”; Redis — “Required once you run more than one instance”; LiteLLM services — “Stateless; run 2+ replicas behind a load balancer”. The card’s word “optional” traces to the COMPETITOR’s page, which contradicts itself elsewhere (“You run all three.”). Docker is one of three documented paths (compose, Helm/K8s, Terraform).
- vendor docs (LiteLLM) — docs.litellm.ai/docs/proxy/prod “Production Best Practices”, verbatim: “Run Redis (7.0 or newer) as soon as you run more than one proxy instance. It shares rate limit counters, router state, and the response cache across instances; without it, each instance enforces limits independently…”. There is an entire docs page titled “What Needs Redis”. Also documents the DB-free mode and what it costs you: “no key management, spend tracking, or UI persistence… authentication falls back to the master key alone.”
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69d37bd9000000001a037427 ★ READ END TO END 2026-08-17 (signed URL). 栗卷卷卷_, 「小心 OpenRouter 费用刺客」. 37 likes / 40 collects / 28 comments. FIRST-HAND cost surprise and a COST CHANNEL THE 5.5% FRAMING MISSES: a model free on input/output still generated tool-call/OCR charges — 「几个pdf下去直接十几刀没了」. Strongest new 小红书 finding on the economics axis.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69e2305c00000000210041c6 ★ READ END TO END 2026-08-17. 查饵丝-开发版(Cha3rsi). 197 likes / 145 collects / 108 comments — HIGHEST-ENGAGEMENT ON-TOPIC NOTE IN THE WHOLE CORPUS, and the draft never read it. FIRST-HAND loss of access after a top-up with a mainland-bank Visa. ⚠⚠ TITLE AND BODY DISAGREE: the title claims 「真把中国ip给禁用了」 (an IP ban) but THE BODY DESCRIBES NO IP BAN and hedges the cause with 「可能」(maybe) — billing address. QUOTE THE BODY, CARRY THE HEDGE, NEVER THE TITLE.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/6a54ae8f0000000008002f64 ★ READ END TO END 2026-08-17. 小鱼儿, 「OpenRouter 的 10 种坑|避坑及福利指南」. 20 likes / 25 collects / 5 comments. FIRST-HAND: registration/payment eligibility friction for mainland-China users (email domain, mainland billing address, WeChat Pay/Alipay/UnionPay-Visa). Corroborates xhs-69e2305c on the same axis three months later. ⚠ Its 「充值10 credits…每天1000次请求」 free-tier claim was NOT verified against openrouter.ai — do not put on the card face.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69c608ce0000000023006852 ★★ READ END TO END 2026-08-17. 古法编程手艺人, 「PyPI供应链攻击,72分钟应急全记录」. Most detailed independent timeline found. (a) “72 minutes” is NOT a rival to the vendor’s “~40 minutes” — different intervals (upload→public disclosure 10:52→12:02 UTC vs packages-live-before-quarantine). (b) ⚠ 13-MINUTE DISCREPANCY, UNRESOLVED: vendor says packages live 10:39 UTC, this says v1.82.8 uploaded 10:52 UTC — plausibly two packages, two upload times, NOT verified. (c) 「根本不在 GitHub 上——没有对应的提交,没有 release tag」 INDEPENDENTLY CORROBORATES the vendor’s own most self-serving claim (GitHub-source installs clean). Also explicitly fair to the maintainers: 「不是说 LiteLLM 团队有问题」.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69c3667f0000000023027f09 READ END TO END 2026-08-17. 硅谷阿羊, 127 likes / 96 collects — highest-engagement security note. Key scope fact: 「不需要import,安装就中招」 — INSTALLATION ALONE SUFFICES, no import required (.pth auto-execution). Corroborates xhs-69c608ce on mechanism. A news summary, not first-hand: citable as a source, counted as a voice nowhere.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/69c4814900000000220256c8 READ END TO END 2026-08-17. 吴迪 乐卓博大学, 42 likes. ⚠ DISCLOSED ACADEMIC STAKE — the same note promotes the author’s own USENIX Security ’25 paper (MalGuard). Takes NO position on OpenRouter vs LiteLLM ⇒ LOGGED AS A SOURCE, NOT COUNTED AS A VOICE. Useful framing only: the risk is the library’s POSITION as middleware.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/ CLUSTER, NOT VOICES. search 「LiteLLM 被投毒 攻陷 供应链」 2026-08-17 returned ~20 on-topic notes, 14 DATED 2026-03-25/26/27 (奥森木 62 likes, 硅谷阿羊 127, 吴迪 42, 路加 13, DeepJerry 8, 阿卷「Karpathy 紧急警告」, 硅基生命观察员, flyingcloud, 极客游, 心花怒放那就放, 小李来喽, Absolutely not., 赛博房哥Cooper, 大A浩南), plus 菜菜爱编程 2026-04-04 and 柚子柚子 2026-04-14. USE: independent multi-author DATED confirmation that the Chinese corpus placed the incident in LATE MARCH 2026 — the card’s central re-dating. DO NOT count 14 near-identical news summaries as 14 voices.
- xiaohongshu (CN) — www.xiaohongshu.com/search_result/6a8262c8000000002202d150 EXCLUDED. 抽屉外, 1 like. ⚠ Title asserts 「三个月估值从 13 亿涨到 70 亿」 but THE BODY CONTAINS NO SOURCE AND NO VALUATION DISCUSSION AT ALL — the body is engagement bait (「关注我,每天拆一组被写乱的数字」). MUST NOT be used for the valuation/price question. Logged so nobody re-reads the title and trusts it.
- bilibili (CN) — www.bilibili.com/video/BV11s7v69EqV READ 2026-08-17 — NOW DATED (2026-06-25 15:33) with counts as-read: 4,236 views / 80 likes / 122 favs / 20 replies. 程序员暮闲. Uploader-written description usable per project rule (B站 has no subtitle track; spoken content never cited). ⚠ Compares LiteLLM to NEW API, not to OpenRouter: 「LiteLLM 更适合企业级 AI Gateway、Agent 应用、模型调用治理和工程化集成」. Positioning claim, not a switch report.
- bilibili (CN) — www.bilibili.com/video/BV1QE756MEQa READ 2026-08-17 — NOW DATED (2026-07-08 03:04), 1,491 views / 23 likes / 44 favs / 3 replies. 鱼跃于渊Bit, 「AI网关工具LiteLLM从Python迁移至Rust」. ⚠ Description asserts 「网关开销降低至 1 毫秒以下」 and 「内存占用控制在 100MB 以内」 — UPLOADER-ASSERTED, almost certainly restating LiteLLM’s own announcement, NOT independently measured. THESE NUMBERS MUST NOT GO ON THE CARD FACE. Usable only to date the Python→Rust story in the Chinese corpus.
- bilibili (CN) — www.bilibili.com/video/BV17n3b6rEcY READ 2026-08-17 — NOW DATED (2026-07-30 13:46), 2,976 views / 49 likes / 144 favs / 15 replies. 程序员暮闲, 「告别 LiteLLM」. Description carries a real operator-cost signal: 「LiteLLM 的功能越来越丰富,但对内存和硬件资源的要求也越来越高」. ⚠ The 「快 50 倍」 in the title is an unmethodolgised uploader/vendor performance claim — NOT carried as fact. 📌 SAME uploader also published the LiteLLM getting-started tutorial (BV1EGNGzhEQj, 10,341 views) five weeks earlier: one channel’s editorial arc, not a population trend.
- bilibili (CN) — www.bilibili.com/video/BV1XbRtBBEkA READ 2026-08-17 — NOW DATED (2026-05-06 15:47) but still NOT USABLE. laozibaqingdiao, 「Apimart vs LiteLLM Proxy:自建网关还是托管聚合」 — THIS CARD’S QUESTION IN CHINESE, but the description is MERELY THE TITLE REPEATED, and engagement is negligible (60 views, 0 replies). Existence and date only; no substantive content to cite. Logged honestly rather than dressed up.
- bilibili (CN) — www.bilibili.com/ PATTERN, not a voice. search 「LiteLLM 网关」 2026-08-17 also surfaced BV1n3obBoE99 「GoModel…比 LiteLLM 快 14.5 倍」, BV14KT76mEYq 「aiway:基于Rust实现的轻量 API + AI 网关」 and BV17n3b6rEcY 「…快 50 倍…Bifrost」. The Chinese video corpus around LiteLLM is substantially REPLACEMENT MARKETING with unmethodolgised speed claims — a reason to DISCOUNT the corpus, not to quote it.
- tooling — switchcards.uk/engineering ENVIRONMENT FINDING, recorded for future sweeps. mcp__agent-reach__get_status returned 「状态:3/16 个渠道可用」 and listed 小红书 and B站 among ten NOT-YET-UNLOCKED channels — yet BOTH worked on the very next call (search returned 18 signed 小红书 URLs and 20 B站 videos; read returned full bodies and full B站 metadata). ⇒ get_status output is NOT sufficient evidence that a channel is unavailable; a channel is a coverage gap only after search/read are ATTEMPTED AND FAIL, with the error quoted. Directly relevant to bug #39.
- zenn (JP) — zenn.dev/hikotty/articles/e536274dc77a4f ★★ THE STRONGEST NEW FINDING. FIRST-HAND: deployed the AWS-official LiteLLM reference stack. 13 likes. Full body read 2026-08-17 via the Zenn article API (returns body_html + exact published_at). Gives an ITEMISED $378/month always-on infra figure (ECS ~$115, multi-AZ RDS ~$98, NAT ~$50, Redis ~$25, ALB ~$25, misc ~$65). Through OpenRouter’s own formula that moves the crossover to ~$6,900/month — roughly 2× the vendor’s $3,600. ⚠ HONEST CAVEAT: this is the repository README’s ESTIMATE, not a settled bill, and the author says so. NOT derivative of the vendor page: never mentions $3,600, 5.5% or a crossover. No stake disclosed or detected.
- zenn (JP) — zenn.dev/yosh1/articles/litellm-langfuse-hybrid-setup ★ THE OTHER BRACKET. FIRST-HAND: LiteLLM + Langfuse on one 4 vCPU / 8 GB Tokyo VPS at ¥3,000–6,000/month (~$20–40) — about 10× below hikotty’s AWS reference stack, which is why the crossover is a RANGE, not a number. Also first-hand on the operator burden: co-locating Langfuse v3 (which embeds ClickHouse) with LiteLLM + PostgreSQL + Redis on 8GB “immediately falls over with OOM”. No stake — explicitly calls the VPS choice incidental and names a cheaper rival. Full body read 2026-08-17.
- zenn (JP) — zenn.dev/seiryu_dev/articles/llm-gateway-solo-ops-6-pitfalls ★ INDEPENDENT ARRIVAL AT THIS CARD’S VERDICT, in a language the card had never read. FIRST-HAND solo operator running BOTH: client-* routes are wired only to direct provider APIs or local Ollama, so “for breadth-type paths like OpenRouter no resolution target exists in the first place” — data residency made a ROUTING property rather than a policy. Six documented failures in one month. ⚠ SELF-SCOPED HONESTLY: “about one month, not a year”, and the config is withheld because it carries client data ⇒ NOT independently reproducible. No stake. Full body read 2026-08-17.
- zenn (JP) — zenn.dev/okamyuji/articles/golang-litellm-alternative-single-binary LEFT LiteLLM — 43 likes, the highest-engagement Japanese LiteLLM article found. ⚠ STAKE, FLAGGED: the author is showcasing their own OSS (go-llm-agent, MIT). Citable because it argues against itself: “If you are building an in-house LLM gateway hit by hundreds of developers, LiteLLM, with its long operational track record, is overwhelmingly advantageous”, and endorses running both. Reasons for leaving are PACKAGING and SCOPE (Python dependency tree, unused features), NOT price. Full body read 2026-08-17.
- juejin (CN) — juejin.cn/post/7532883459156213775 ⚠ DIRECT COMPETITOR — Alibaba Cloud’s own cloud-native team comparing OpenRouter to Higress, Alibaba’s gateway product. CITED FOR THE FEE NUMBER ONLY, NEVER THE VERDICT. Corroborates BOTH prongs from a hostile source: 5.5% toll on credit top-up (5% crypto) and a separate 5% BYOK toll. Evidentially useful precisely because the source has an interest in OpenRouter looking expensive. 556 views. Read 2026-08-17.
- zhihu (CN) — zhuanlan.zhihu.com/p/2013962989359870208 ⚠⚠ EXCLUDED AS EVIDENCE, LOGGED AS A CONTAMINANT. Affiliate marketing — every mention of the product it sells is a tracked link (utm_source=zhihu&utm_medium=article&utm_campaign=dev_community). It asserts OpenRouter “adds a layer of its own profit on top of the official price”, which is FLATLY FALSE against OpenRouter’s documented 0% markup plus a separate credit-purchase fee. Recorded because it evidences a real phenomenon: Chinese-language relay marketing systematically misdescribes OpenRouter’s pricing ⇒ Chinese “OpenRouter is expensive” sentiment is weighted down on this card unless the author shows workings.
- zenn/qiita (JP) — zenn.dev/agdexai/articles/llm-gateway-comparison-2026 EXCLUDED — SEO/commercial, closes by advertising the author’s own directory. ⚠ CROSS-POSTED VERBATIM to Qiita (qiita.com/agdexai/items/be338f753ddd8ce5cd70, 2026-08-04) ⇒ THE SAME TEXT ON TWO PLATFORMS IS ONE SOURCE, NOT TWO — logged explicitly so a later sweep does not double-count it. Contains no first-hand run, no cost arithmetic, and never mentions the 5.5% fee despite being a pricing comparison.
- qiita (JP) — qiita.com/locallab/items/f1fbb784db79d27bc35d EXCLUDED — representative of ~10 near-identical machine-generated “Claude Code × OpenRouter free models” posts between 2026-07-29 and 2026-08-17. ONE TEMPLATE REPOSTED; ZERO VOICES. Logged so a later sweep does not mistake the volume for community interest.
- hatena / corporate blog (JP) — engineering.dena.com/blog/2026/08/ai-token-cost-report/ DECLARED GAP — TITLE-ONLY, BODY NOT READ. A named Japanese company publishing on AI token-cost governance; the closest thing to an enterprise JP cost datapoint the sweep saw. Named here and in the coverage footer so its absence is visible rather than silent.
- zhihu (CN) — www.zhihu.com/search?q=LiteLLM&type=content PARTIAL GAP, ERROR QUOTED. Direct fetch: `HTTP/2 403`, `server: BLB/25.12.0.2`, returning a JS anti-bot shell only. Via reader proxy: `Title: 安全验证 - 知乎` / `Warning: This page maybe requiring CAPTCHA, please make sure you are authorized to access this page.` / 「系统监测到您的网络环境存在异常…」. ⚠ THE CAPTCHA WAS DELIBERATELY NOT ATTEMPTED — defeating bot-detection is out of bounds. NOTE: individual zhuanlan.zhihu.com/p/<id> articles ARE readable ~50% of the time (3 read); the failures were one `403: Forbidden`, one removed article (「你似乎来到了没有知识存在的荒原」) and one login wall. So 知乎 SEARCH is the gap, not 知乎 as a platform.
- csdn (CN) — blog.csdn.net/ PAYWALLED. Reachable but gated: 「最低0.47元/天 解锁文章」 (“unlock the article from ¥0.47/day”) — intro only, no body. Declared as a gap.
- Hacker News — news.ycombinator.com/item?id=47501426 ★★ THE THREAD THE ORIGINAL SWEEP MISSED. "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised", by dot_treo, links issue #24512. 938 points / 496 comments as read 2026-08-17 — the MOST-DISCUSSED LiteLLM story in HN history, and the direct refutation of the card's retired "zero discussion" claim. Carries a first-hand leaving posture (bfeynman: "most likely move away from it entirely") with its hedge intact.
- Hacker News — news.ycombinator.com/item?id=47501729 ⚠ NOT AN INDEPENDENT SIGNAL — DO NOT COUNT. 739 points but exactly 1 comment, because a moderator merged the discussion: "Comments moved to https://news.ycombinator.com/item?id=47501426, which was posted first." (dang). Logged so a later sweep does not add 938 + 739 as two threads — that is the summing error already registered against this project.
- Hacker News — news.ycombinator.com/item?id=47531967 ★ THE DISCOVERER ON THE RECORD. "My minute-by-minute response to the LiteLLM malware attack", 441 pts / 147 comments, submitted by Fibonar, linking futuresearch.ai/blog/litellm-attack-transcript/. His own comment: "Callum here, I was the developer that first discovered and reported the litellm vulnerability on Tuesday." Independently corroborates the timeline shape reconstructed second-hand in quotes.md §10d. ⚠ THE LINKED TRANSCRIPT WAS NOT FETCHED — thread and comment only. Declared gap.
- Hacker News — news.ycombinator.com/item?id=47596739 ★★ A NAMED DOWNSTREAM VICTIM — evidence the card entirely lacked, and it points AGAINST the self-hosted side. "Mercor says it was hit by cyberattack tied to compromise LiteLLM" (TechCrunch), 151 pts / 31 comments. Thread also reports LiteLLM changing compliance vendors (Delve -> Vanta). ⚠ THE TECHCRUNCH ARTICLE WAS NOT FETCHED — headline and thread comments only; the card therefore states no scope, no victim count and no impact. Declared gap.
- exchangerate-api.com — open.er-api.com/v6/latest/USD FX rate used to convert the ¥3,000–6,000 VPS figure for the reader. Fetched 2026-08-17; provider field "https://www.exchangerate-api.com", time_last_update_utc "Mon, 17 Aug 2026 00:02:31 +0000", JPY 159.20446. ⚠ A SPOT RATE ON ONE DAY applied to a price quoted in yen in April 2026 — a convenience conversion, NOT a claim about what that operator paid in dollars at the time. The yen figure is the receipted one; the dollars are derived. Logged because a card-face citation must have a ledger row: an earlier revision cited this rate with a timestamp and no source row, which is the defect this row closes.
- cisa.gov — www.cisa.gov/known-exploited-vulnerabilities-catalog CISA Known Exploited Vulnerabilities catalogue. Fetched 2026-08-17 from the JSON feed (sites/default/files/feeds/known_exploited_vulnerabilities.json): catalogVersion 2026.08.17, dateReleased 2026-08-17T13:47:08.5067Z, count 1666. Exactly TWO BerriAI/LiteLLM entries — CVE-2026-42208 "BerriAI LiteLLM SQL Injection Vulnerability" dateAdded 2026-05-08, and CVE-2026-42271 "BerriAI LiteLLM Command Injection Vulnerability" dateAdded 2026-06-08. KEV listing means exploitation observed in the wild. Both are already inside the 12-advisory set, so this is severity information, not an additional count. Logged because a card-face citation must have a ledger row.
- github — api.github.com/repos/BerriAI/litellm Live repository metadata, co-citation for the repos.ecosyste.ms figures. Read 2026-08-17. Added because a verifier saw the ecosyste.ms endpoint return HTTP 402 under rate limiting (it returns 200 on re-check), and a single rate-limited mirror should not red the live gate. ⚠ The two sources differ slightly by design — ecosyste.ms is a MIRROR with last_synced_at 2026-08-16T07:39:46.757Z, so its 56,438 stars lag the live API by about a day. The card cites the mirror figures WITH that lag disclosed; this row is the direct check.
Straight answers
- when was the litellm supply chain attack?
- 2026-03-24, not August. The compromised packages
litellm==1.82.7and1.82.8were live on PyPI for about 40 minutes before quarantine, per BerriAI’s own postmortem — which separately puts the window in which apipinstall could have been affected at 10:39–16:00 UTC that day — and GitHub’s advisoryGHSA-5mg7-485q-xm76is dated 2026-03-25. Fourteen Chinese-language notes independently date it to 2026-03-25/26/27. The August 2026 news wave is follow-up coverage, not a new compromise; this card read that coverage at headline level only and carries none of its figures. This card states no root cause — the incident issue contradicts itself on that point. - was i affected by the litellm breach?
- The window that matters is longer than the one in the headlines. BerriAI’s postmortem says you may be affected if “You installed or upgraded LiteLLM via
pipon March 24, 2026, between 10:39 UTC and 16:00 UTC” — 5h21m, not the ~40 minutes the packages were live on PyPI, and not only if you were unpinned: the same section names unpinned transitive dependencies (through agent frameworks, MCP servers or orchestration tools) and Docker images built during the window that ranpip install litellmunpinned. Installing was enough on its own — the payload ran on install, not on import. Not affected: the official LiteLLM Proxy Docker image, which “pins dependencies in requirements.txt”, and installs from the GitHub repository, which was “not compromised”. If you were inside that window, the postmortem’s instruction is to rotate every credential the environment could see. - does openrouter charge a fee?
- Yes — 5.5% on pay-as-you-go credit purchases with a $0.80 minimum, and 5.0% on crypto, confirmed live on OpenRouter’s own pages. Two caveats this card checked: the $0.80 minimum and the crypto rate are not on the pricing page at all — they live in the docs FAQ — and “Fee discounts available” appears only in the Enterprise cell — the pay-as-you-go cell is a flat 5.5%, and the same page says “We do not discount inference.” And the exception that matters most: bring your own provider keys and OpenRouter charges nothing below $25,000/month. Verbatim: “BYOK has a plan-dependent free allowance measured by list-price inference cost, not request count. Pay-as-you-go includes [$25,000] per month with no BYOK fee, while Enterprise includes [$200,000].” Separately, a “free” model can still bill you for tool calls: one first-hand account lost ten-odd dollars to the OCR path on a few PDFs.
- is litellm cheaper than openrouter?
- It depends on spend and on an infrastructure figure the vendor never justifies. OpenRouter’s own comparison says that at roughly $200/month of infrastructure, self-hosted LiteLLM gets cheaper once model spend passes about $3,600/month. But two independent dated deployments put real infra about 10× apart — about $19–38/month for a single VPS (¥3,000–6,000 at 159.20 JPY/USD, rate fetched 2026-08-17) and $378/month for the AWS-official reference stack — which through the same formula gives crossovers from roughly $340 to roughly $6,900 a month. Across 21 posts swept for this card — 12 Japanese, 9 Chinese — the $3,600 figure is never independently reproduced; it stays vendor-sourced. Treat it as a range you compute from your own infra bill, not a threshold. And check one term before you compute anything: if you bring your own provider keys, OpenRouter charges nothing below $25,000/month of list-price inference ($200,000 on Enterprise), 5% above it. That allowance sits well above the top of the range, so for a BYOK team the fee case for self-hosting mostly does not arise.
- is litellm open source? what licence is it?
- MIT — with one carve-out. LiteLLM’s root
LICENSEreads: everything outside theenterprise/directory is “available under the MIT license” (Copyright (c) 2023 Berri AI);enterprise/is governed by the separate BerriAI Enterprise License, which permits development and testing but requires a paid seat-based subscription for production use. GitHub and repos.ecosyste.ms both report the licence field asother/NOASSERTION — that is a detection artefact caused by the carve-out preamble, not an unclear licence. - is litellm safe to self-host?
- That is the operator cost, and it is larger than the fee debate suggests.
BerriAI/litellmhas 12 published security advisories in 2026 — 3 critical, 5 high, 2 medium, 2 low — dated 2026-04-03 through 2026-06-30. One, CVE-2026-42271, let any authenticated user run arbitrary commands on the host because the endpoints had “no role check”; it is fixed in1.83.7. Two of the twelve are in CISA’s Known Exploited Vulnerabilities catalogue — CVE-2026-42208 and CVE-2026-42271 — meaning exploitation observed in the wild. Self-hosting means you own that patch queue, and the crossover arithmetic — whose range runs from roughly $340 to roughly $6,900 a month depending on your infrastructure bill — does not price it at all. - did stripe buy openrouter?
- Reported, not confirmed. Bloomberg reported on 2026-08-16 that Stripe had “finalized an agreement” at more than $7 billion, “according to people familiar with the matter” — while saying in the same story that “The final price for the acquisition could change”. Stripe “doesn’t comment on rumors or speculation”, OpenRouter declined to comment, and OpenRouter’s own blog published a routine product post the next morning without mentioning it. The ~$10B reported in July and the $7B+ in August are the same deal repriced, not two conflicting figures.
- should i leave openrouter because of the stripe acquisition?
- Nothing in this sweep shows the API changing — across five stories we read, none states what happens to the product, the API or the pricing. A practitioner in that thread says the switching cost is low precisely because a router is thin — “as easy to switch from as the model providers they proxy”. So the acquisition is a reason to watch, not to migrate. Spend, data residency, and — if you are in mainland China — account and payment eligibility are what actually decide it.
Stuck on a different switch?
If the card doesn't exist yet, request it — free, like everything here. Full sweep, weighted verdict, and one email the moment it's published.
Request a card