
Criminal AI, powered by OpenRouter
Three criminal AI storefronts, one legitimate backend.
Kriminal, DadGPT, and WormGPT are three of the most recognizable tools in the criminal AI marketplace today. Kriminal and DadGPT sell themselves as unrestricted AI: no filters, no refusals, built specifically to say “yes” where a mainstream model would say “no.” WormGPT takes the opposite approach, marketing itself as an “Ethical Hacking AI” for “cybersecurity professionals” — camouflage that lets it hide in plain sight. All three live on the clearnet, a mere Google search away.
They’d like you to believe that they’re AI models made by and for the cybercrime underground. None of them disclose what’s actually running underneath.
All three point back to the same legitimate gateway: OpenRouter.
OpenRouter is a critical component of the legitimate AI ecosystem, but it doesn’t build AI. It’s a single gateway that connects customers to hundreds of AI models, including models from well-known AI companies like OpenAI and Anthropic, so they don’t have to manage different APIs or direct relationships with each one. That convenience is exactly why it works so well here: it lets three unrelated operators leverage a single shortcut, instead of building anything themselves, and switch models easily the moment one starts saying “no” instead of “yes.” Kriminal is the clearest example, as we covered in August: its own code shows Grok as its primary engine, called directly through xAI, with Mistral Large and Llama 3.3 accessed through OpenRouter for specialist tasks. These are powerful AI models from established companies with robust safety measures specifically built to stop their models from doing things criminals find useful. Kriminal wraps the same jailbreak around every prompt, whether it’s headed to Grok directly or routed to OpenRouter’s specialist models. Nothing else changed.
Shut one down, another pops up
This arrangement also means there’s no dedicated criminal infrastructure to target and shut down. OpenRouter doesn’t filter the content passing through it, so understanding what these storefronts’ users are actually doing would mean monitoring dozens, sometimes hundreds, of models spread across as many different companies, simultaneously. That isn’t to suggest that OpenRouter is complicit in this activity: it’s a routing layer, not a moderator, and the same absence of filtering that shields criminal storefronts applies to every legitimate customer using the service, too. Any legitimate company reaching AI models through OpenRouter runs on the same tracks these storefronts do, and the traffic looks identical either way. Legitimate traffic becomes the haystack, unwittingly hiding the needle.
Criminals’ access to AI tools isn’t dependent on any one storefront staying online either. If Kriminal or DadGPT disappear tomorrow morning, there are competitors ready to take their business, and the same setup, a jailbreak prompt in front of borrowed access, could be rebuilt under a new name by tomorrow afternoon. By routing through vendors like OpenRouter, there’s no unique infrastructure to lose to takedowns or law enforcement actions, which means there’s no lasting win in shutting any single storefront down.
What runs underneath
Kriminal runs on Grok directly, plus Mistral Large and Llama 3.3 through OpenRouter, as its own client-side code explains.
// Source: https://kriminal.ai/assets/index-CsvTF3_-.js
const R = [
{
key: "openrouter",
name: "OpenRouter",
dashboardUrl: "https://openrouter.ai/settings/credits",
description: "Routes agent specialist models (Mistral Large, Llama 3.3)",
models: "mistralai/mistral-large-2411 · meta-llama/llama-3.3-70b-instruct"
}, {
key: "xai",
name: "xAI (Grok)",
dashboardUrl: "https://console.x.ai",
description: "Primary inference engine for all chat and agent runs",
models: "grok-3-fast · grok-3 · grok-3-mini · vision models"
}, {
key: "tavily",
name: "Tavily Search",
dashboardUrl: "https://app.tavily.com",
description: "Real-time web search for live search mode and agent tools",
models: "tavily-search-context"
}
];
DadGPT exposes its reliance on OpenRouter in its connect-src Content-Security-Policy directive (a short list of domains the site is permitted to make client-side requests using tools like fetch, XHR, or WebSockets) alongside four other AI vendors.
$ curl -sI https://www.dadgpt.live/
HTTP/2 200
content-security-policy: … connect-src 'self' https://openrouter.ai https://api.deepseek.com https://agentrouter.org https://api.aimlapi.com https://dashscope-intl.aliyuncs.com https://telegram.org; …
WormGPT’s admin panel carries the same tell: an OpenRouter credit-balance call built into it.
// Source: https://wormgpt.net/assets/js/common.js?v=20260510v
s' + (period ? `&period=${encodeURIComponent(period)}` : '')), adminOpenRouterCredits: () => API.req('admin.php?action=openRouterCredits'), adminU
)}` : '')), adminOpenRouterCredits: () => API.req('admin.php?action=openRouterCredits'), adminUsers: () => API.req('admin.php?action=users'), ad
The storefronts are disposable. The gateway isn’t.
Our own research, detailed in Cybercrime in the age of AI, found that Mythos-class AI is likely to reach criminal marketplaces in a matter of months. By its own maker’s account, one of these models has already found and exploited zero-days across every major operating system and browser it was tested against. Independent testers went further: one of these models completed a simulated corporate network takeover start to finish, a job that takes human professionals roughly 20 hours to complete. This isn’t a faster version of what today’s storefronts already sell. It’s the difference between a tool that writes a phishing email and one that finds its own way into the network. And when it arrives, it won’t need new criminal infrastructure. It’ll use the same gateway, the same jailbreak-and-resell playbook, the same storefronts already open for business today.
That’s the part worth planning for now. The next wave of criminal AI won’t show up as a new domain to blocklist or a new tool to fingerprint. It’ll look exactly like the AI traffic already flowing through everyday networks, because it will be running on the same rented, undifferentiated backbone. Waiting for it to look different is waiting for a pattern this space has never followed.