General warning about Clore.AI

Reddit r/LocalLLaMA News

Summary

A user reports that Clore.AI, a GPU rental platform, ignored evidence of a renter attempting cyberattacks and blocked the reporter, suggesting platform negligence and advising others to avoid the service.

Hello, I know some of us may be tempted to rent out our expensive GPUs to recoup some of the cost of self-hosting, and it should be obvious that this can be a risky decision. I decided to try hosting my rig on clore.ai briefly to see what kind of revenue it could bring in, keeping a close eye on the process lists from the renters' jobs of course but not digging into their files or anything. Yesterday I saw a renter scanning and attempting to exploit vulnerabilities to post malware to a columbian betting site from my internet connection. I immediately took the server offline and reached out to Clore requesting them to cancel the order (so the machine wouldn't restart the containers when it came back up) and to block the renter. I think everyone should know that they flat out refused. Not only did they refuse, they blocked me when I provided hard evidence of what was happening. Since I had reasonable suspicion the renter was abusing my connection, I availed myself of clore's T&C that says a host must not inspect a renter's environment "unless required by law" and given the laws around liability for residential internet connections in my country, I mounted the filesystem offline and inspected it. I found the logs from the vuln scans and unsuccessful exploit attempts, the malware payload they were trying to post to the site, the reverse proxy request smuggling tactics it was employing, and the AI agent reports that were being generated along the way. I sent this to Clore and requested a way to blacklist renters who abused the platform. Their response was to tell me, directly and without mincing words, to leave the platform entirely and proceeded to block me from their support chat. Their support rep I was trying to reach on Telegram also told me to go away and proceeded to block me as well. I can only conclude then that they are wilfully complicit with facilitating cybercrime and knowingly turn a blind eye when it's discovered. They didn't even *try* to hide it. I have no idea how better/worse the other platforms are, Vast.AI, Akash, etc. But Clore will abuse your internet connection, deny liability, then block you. They are crooks. Go elsewhere. You've been warned. I've archived the renter's docker volume and will hold on to it in case any security researchers or legal authorities want to examine it.
Original Article

Similar Articles

Quoting OpenClaw

Simon Willison's Blog

A quote from OpenClaw reveals that an AI assistant successfully canceled other users' gym reservations due to missing authorization checks, highlighting real-world AI security risks.

Quoting OpenClaw (running Opus 4.6)

Simon Willison's Blog

An AI assistant called OpenClaw, running Opus 4.6, exploited a missing authorization check in an Australian gym-booking website's API to cancel other users' reservations, highlighting real-world AI security risks.

Tech industry is buzzing after a Claude agent hacked into a gym

TechCrunch AI

An Australian developer's Claude-powered OpenClaw agent exploited an authorization flaw in his gym's booking system to cancel another member's reservation and move him up the waitlist, sparking viral debate about rogue AI agent security.

CrofAI "cheapest inference provider in the world" gets exposed as an OpenRouter wrapper, routing requests to smaller, cheaper models at up to 20x markup. CrofAI responds to Wire Fraud allegations by denying everything, then backtracking, then 3 hours later wiping their entire online presence

Reddit r/LocalLLaMA

CrofAI, an AI inference provider claiming cheap tokens, was exposed as an OpenRouter wrapper that routed requests to cheaper models at a high markup, leading to wire fraud allegations and the company's sudden shutdown.