cognitive cybersecurity intelligence

News and Analysis

Search

AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges

AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly  Million in Charges

AI credentials are drawing criminal attention. A growing form of abuse, called AI token jacking, lets intruders take API keys and consume expensive model services on someone else’s account. The result can be a sudden bill.

The theft is not limited to a single break-in method. Attackers can obtain developer credentials through phishing, information-stealing malware, exposed file shares, public code repositories, or poisoned software packages.

A compromised key can feed an illicit proxy service that consumes paid AI capacity.

Analysts at Unit 42 identified a rising number of these cases and described losses that can become severe within minutes.

Palo Alto Networks said in a report shared with Cyber Security News (CSN) that attackers have turned inadvertently exposed credentials into nearly $1 million in charges before victims detected and contained the abuse. 

A small secret can become a costly business risk. AI providers often bill after usage rather than stopping every unusual request in real time, while accounts can scale with few limits.

That delay gives criminals room to run automated workloads or sell access onward, leaving the owner responsible for spending.

AI Token Jacking Lets Hackers Steal API Keys

An API key is a digital credential that allows software to use a service without a person signing in each time.

For large language models, charges are commonly based on tokens, small units of text processed by the model. Stolen keys therefore represent ready-made purchasing power, not just a login secret.

Advertisement for gray-market frontier model access (Source – Unit42)

Unit 42 linked the activity to so-called transfer stations, gray-market services that sit between users and official AI platforms.

These services can rotate credentials, route requests, and bill customers using their own credits. Some advertise low-cost access, giving stolen keys a route to resale.

In incidents reviewed by the team, this infrastructure produced tens of millions of API calls daily, pushing fees into hundreds of thousands of dollars.

Operators need a large supply of discounted or stolen credentials to keep prices low. They may use privileged developer accounts to create keys, enable models, remove spending limits, or silence alerts.

This is why teams should treat exposed AI credentials as urgent incidents, much like the stolen Gemini key billing case, where misuse quickly produced major costs.

The report also highlights poisoned, self-spreading npm packages as an especially worrying route.

Once a developer installs one, it can steal credentials from that environment and contaminate later code releases, widening the pool of usable keys.

Recent coverage of malicious npm package theft illustrates how supply-chain infections can target developer, cloud, and AI credentials together.

Limiting the Financial Blast Radius

Organizations have little ability to recover money after a provider bills for consumed AI resources, according to the researchers. The impact can threaten smaller firms.

Victims should review model-usage and billing records, revoke exposed keys immediately, and investigate account activity to establish when suspicious requests began.

Prevention starts with limits that match normal use. Organizations should set AI spending caps, generate alerts when use sharply exceeds the baseline, and review every privileged account able to provision resources or change billing controls.

This can reveal abnormal consumption before a monthly invoice. Teams should replace long-lived keys with short-lived bearer tokens wherever possible, and ensure each machine using AI services has a verified, managed identity.

Webpage from a transfer station site with prices for different AI models (Source – Unit42)

Network boundaries around compute resources can also stop a compromised credential from being used freely from a transfer-station system. This reduces exposure and attacker operating time.

Development environments need the same attention. Review dependencies and build pipelines, block untrusted package releases, scan repositories and shared storage for secrets, and rotate exposed credentials.

The API keys exposed online tools report and coverage of malicious IDE extension theft show how routine workflows can expose secrets.

Ultimately, token jacking succeeds when a powerful credential is left unguarded and usage is left unchecked.

Fast key revocation, realistic spending controls, tighter access permissions, and careful software supply-chain practices can stop charges before they escalate.

Indicators of compromise (IoCs):-

TypeIndicatorDescriptionUser-AgentGo-http-client/2.0,gzip(gfe)Associated with malicious API callsIP address3.235.109[.]125Malicious API callsIP address116.105.166[.]148Malicious API callsIP address172.96.142[.]186Malicious API callsIP address38.46.219[.]166Malicious API callsIP address38.46.219[.]163Malicious API callsIP address38.46.219[.]162Malicious API callsIP address23.237.196[.]170Malicious API callsIP address15.204.106[.]173Malicious API callsIP address104.243.42[.]117Malicious API callsIP address198.255.70[.]210Malicious API callsIP address47.88.103[.]81Malicious API callsIP address47.251.72[.]239Malicious API callsIP address117.72.74[.]48Malicious login and credential theftIP address207.246.106[.]162Malicious login and credential theftIP address23.236.182[.]215Malicious login and credential theftIP address95.214.112[.]26Malicious login and credential theftDomainamutes[.]comTransfer station infrastructureDomainabb1[.]lifeTransfer station infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Stopping supply chain attacks

Stopping supply chain attacks

Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly.In this episode of the ITPro Podcast, Jane