Skip to main content

Cybersecurity Tokenomics: Denial of Wallet Attacks and the Cost of SOC Operations | Kaspersky official blog

0
Medium
Analysisdosai
Published: 10/07/2026 (10/07/2026, 19:13:03 UTC)
Source: Kaspersky Security Blog

Description

This analysis discusses a new class of denial-of-service attacks called 'denial of wallet' attacks targeting AI token usage in cybersecurity operations centers (SOCs). Attackers can inflate the cost and latency of AI-driven security processes by injecting malicious prompts into data sources processed by AI agents. This can exhaust budgets or trigger security filters, causing silent failures or degraded investigation quality without immediate alerts. The risk includes disruption of AI-based SOC workflows and increased operational costs. Mitigations include strict token usage limits, filtering untrusted data, limiting agent permissions, and using on-premise AI models to reduce reliance on costly cloud APIs.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 19:20:40 UTC

Technical Analysis

The threat involves denial-of-wallet attacks that exploit AI tokenomics by causing AI-based SOCs to overspend tokens during security alert triage and investigations. Attackers inject malicious prompts into data sources (e.g., DNS records, HTTP headers, logs) processed by AI agents, increasing token consumption and latency. This can lead to budget exhaustion or triggering of AI provider security filters, resulting in halted investigations or degraded AI output quality without immediate detection. The attack can silently degrade SOC effectiveness and inflate costs. The analysis highlights the need for cost controls, layered AI model deployment, and strict input filtering to mitigate these risks.

Potential Impact

The impact includes increased operational costs due to token overspending, delayed or halted security investigations, and potential silent failures in AI-driven SOC processes. This can reduce the effectiveness of security monitoring and incident response, potentially leaving threats undetected for extended periods. The attack does not directly compromise systems but targets the availability and reliability of AI-based security operations through resource exhaustion and degraded AI model performance.

Defensive Guidance

No official patch is applicable as this is an operational threat rather than a software vulnerability. Recommended mitigations include: (1) Implement strict token usage limits with multi-level alerts for exceedances; (2) Pre-validate and filter all external and untrusted data inputs to prevent prompt injection and workload inflation; (3) Limit AI agent permissions and capabilities to reduce attack surface; (4) Use deterministic rule-based processing for known repetitive tasks instead of AI; (5) Deploy local on-premise AI models for initial processing to reduce cloud API dependency and cost volatility; (6) Architect AI usage in tiers, reserving costly cloud models for complex cases with human approval; (7) Define clear policies on actions when token limits are reached to avoid silent failures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.kaspersky.com/blog/tokenomics-ai-and-cybersecurity/56523/","fetched":true,"fetchedAt":"2026-10-07T19:20:32.811Z","wordCount":1666}

Threat ID: 6ac69b802cdf04f65675cecc

Added to database: 10/07/2026, 19:20:32 UTC

Last enriched: 10/07/2026, 19:20:40 UTC

Last updated: 10/08/2026, 01:19:23 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses