Cyber Security News

AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges

AI credentials are drawing criminal attention. A growing form of abuse, called AI token jacking, lets intruders take API keys and consume expensive model services on someone else’s account. The result can be a sudden bill.

The theft is not limited to a single break-in method. Attackers can obtain developer credentials through phishing, information-stealing malware, exposed file shares, public code repositories, or poisoned software packages.

A compromised key can feed an illicit proxy service that consumes paid AI capacity.

Analysts at Unit 42 identified a rising number of these cases and described losses that can become severe within minutes.

Palo Alto Networks said in a report shared with Cyber Security News (CSN) that attackers have turned inadvertently exposed credentials into nearly $1 million in charges before victims detected and contained the abuse. 

A small secret can become a costly business risk. AI providers often bill after usage rather than stopping every unusual request in real time, while accounts can scale with few limits.

That delay gives criminals room to run automated workloads or sell access onward, leaving the owner responsible for spending.

AI Token Jacking Lets Hackers Steal API Keys

An API key is a digital credential that allows software to use a service without a person signing in each time.

For large language models, charges are commonly based on tokens, small units of text processed by the model. Stolen keys therefore represent ready-made purchasing power, not just a login secret.

Advertisement for gray-market frontier model access (Source – Unit42)

Unit 42 linked the activity to so-called transfer stations, gray-market services that sit between users and official AI platforms.

These services can rotate credentials, route requests, and bill customers using their own credits. Some advertise low-cost access, giving stolen keys a route to resale.

In incidents reviewed by the team, this infrastructure produced tens of millions of API calls daily, pushing fees into hundreds of thousands of dollars.

Operators need a large supply of discounted or stolen credentials to keep prices low. They may use privileged developer accounts to create keys, enable models, remove spending limits, or silence alerts.

This is why teams should treat exposed AI credentials as urgent incidents, much like the stolen Gemini key billing case, where misuse quickly produced major costs.

The report also highlights poisoned, self-spreading npm packages as an especially worrying route.

Once a developer installs one, it can steal credentials from that environment and contaminate later code releases, widening the pool of usable keys.

Recent coverage of malicious npm package theft illustrates how supply-chain infections can target developer, cloud, and AI credentials together.

Limiting the Financial Blast Radius

Organizations have little ability to recover money after a provider bills for consumed AI resources, according to the researchers. The impact can threaten smaller firms.

Victims should review model-usage and billing records, revoke exposed keys immediately, and investigate account activity to establish when suspicious requests began.

Prevention starts with limits that match normal use. Organizations should set AI spending caps, generate alerts when use sharply exceeds the baseline, and review every privileged account able to provision resources or change billing controls.

This can reveal abnormal consumption before a monthly invoice. Teams should replace long-lived keys with short-lived bearer tokens wherever possible, and ensure each machine using AI services has a verified, managed identity.

Webpage from a transfer station site with prices for different AI models (Source – Unit42)

Network boundaries around compute resources can also stop a compromised credential from being used freely from a transfer-station system. This reduces exposure and attacker operating time.

Development environments need the same attention. Review dependencies and build pipelines, block untrusted package releases, scan repositories and shared storage for secrets, and rotate exposed credentials.

The API keys exposed online tools report and coverage of malicious IDE extension theft show how routine workflows can expose secrets.

Ultimately, token jacking succeeds when a powerful credential is left unguarded and usage is left unchecked.

Fast key revocation, realistic spending controls, tighter access permissions, and careful software supply-chain practices can stop charges before they escalate.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
User-AgentGo-http-client/2.0,gzip(gfe)Associated with malicious API calls
IP address3.235.109[.]125Malicious API calls
IP address116.105.166[.]148Malicious API calls
IP address172.96.142[.]186Malicious API calls
IP address38.46.219[.]166Malicious API calls
IP address38.46.219[.]163Malicious API calls
IP address38.46.219[.]162Malicious API calls
IP address23.237.196[.]170Malicious API calls
IP address15.204.106[.]173Malicious API calls
IP address104.243.42[.]117Malicious API calls
IP address198.255.70[.]210Malicious API calls
IP address47.88.103[.]81Malicious API calls
IP address47.251.72[.]239Malicious API calls
IP address117.72.74[.]48Malicious login and credential theft
IP address207.246.106[.]162Malicious login and credential theft
IP address23.236.182[.]215Malicious login and credential theft
IP address95.214.112[.]26Malicious login and credential theft
Domainamutes[.]comTransfer station infrastructure
Domainabb1[.]lifeTransfer station infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago