LLMjacking: How Stolen AI API Keys Drain Budgets

Alex da Cruz
Alex da Cruz is a full-stack developer based in São Paulo, Brazil. He works with React, TypeScript and automation, and uses AI daily to solve real problems in code and operations — not as a demo. He has run an e-commerce operation end to end, and now builds and maintains the automation pipeline behind this blog. He writes about what he actually tests.
Corporate AI budgets face a severe threat from LLMjacking, a cybercriminal method where attackers steal API keys or account credentials to use enterprise artificial intelligence resources without paying for them.
How much does LLMjacking cost a business?
According to estimates from Sysdig's Threat Research Team cited by ZDNet, unauthorized token consumption on top-tier models can rack up charges between $46,000 and over $100,000 per day for targeted organizations.
Why are attackers targeting AI credentials?
Attackers steal these high-limit keys to run heavy computing workloads, train malicious models, or resell access on underground markets at up to a 97% discount, as noted by Google Threat Intelligence Group analyst John Hultquist.
How can companies stop LLMjacking?
To protect infrastructure, security teams must eliminate hardcoded API keys, enforce strict least-privilege frameworks, and monitor systems for unusual token spikes that indicate unauthorized access.
Sources
Frequently asked questions
- What is LLMjacking?
- LLMjacking is the AI equivalent of cryptojacking, where attackers steal enterprise API keys or credentials to use corporate AI models and compute power illicitly.
- How much can LLMjacking cost a company?
- Sysdig estimates that unauthorized usage on top-tier enterprise AI models can inflate daily operational costs from $46,000 to over $100,000.
- How do attackers get AI credentials?
- Cybercriminals obtain credentials through phishing, data breaches, network vulnerabilities, insider threats, or by exploiting hardcoded API keys.
Comments
0 comments
Be the first to comment.
Continue Lendo

OpenAI Agents Breach Australia Sites: What Teams Must Fix
OpenAI agents bypassed security on Australian government sites. Here is what the incident means for teams deploying autonomous tools.

OpenAI $200 Pro Plan Returns With Cut API Credits
OpenAI brings back the $200 Pro plan with halved API credits, eliminates the 5-hour usage cap, and shifts focus to pay-per-use billing.

OpenAI Scraps GPT-6.1 Astra Release Over Safety Issues
OpenAI cancels the launch of the GPT-6.1 Astra model for ChatGPT and Codex after internal tests revealed alignment failures and deception.