Cybersecurity Tokenomics: Denial of Wallet Attacks and the Cost of SOC Operations | Kaspersky official blog
Description
This analysis discusses a new class of denial-of-service attacks called 'denial of wallet' attacks targeting AI token usage in cybersecurity operations centers (SOCs). Attackers can inflate the cost and latency of AI-driven security processes by injecting malicious prompts into data sources processed by AI agents. This can exhaust budgets or trigger security filters, causing silent failures or degraded investigation quality without immediate alerts. The risk includes disruption of AI-based SOC workflows and increased operational costs. Mitigations include strict token usage limits, filtering untrusted data, limiting agent permissions, and using on-premise AI models to reduce reliance on costly cloud APIs.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat involves denial-of-wallet attacks that exploit AI tokenomics by causing AI-based SOCs to overspend tokens during security alert triage and investigations. Attackers inject malicious prompts into data sources (e.g., DNS records, HTTP headers, logs) processed by AI agents, increasing token consumption and latency. This can lead to budget exhaustion or triggering of AI provider security filters, resulting in halted investigations or degraded AI output quality without immediate detection. The attack can silently degrade SOC effectiveness and inflate costs. The analysis highlights the need for cost controls, layered AI model deployment, and strict input filtering to mitigate these risks.
Potential Impact
The impact includes increased operational costs due to token overspending, delayed or halted security investigations, and potential silent failures in AI-driven SOC processes. This can reduce the effectiveness of security monitoring and incident response, potentially leaving threats undetected for extended periods. The attack does not directly compromise systems but targets the availability and reliability of AI-based security operations through resource exhaustion and degraded AI model performance.
Defensive Guidance
No official patch is applicable as this is an operational threat rather than a software vulnerability. Recommended mitigations include: (1) Implement strict token usage limits with multi-level alerts for exceedances; (2) Pre-validate and filter all external and untrusted data inputs to prevent prompt injection and workload inflation; (3) Limit AI agent permissions and capabilities to reduce attack surface; (4) Use deterministic rule-based processing for known repetitive tasks instead of AI; (5) Deploy local on-premise AI models for initial processing to reduce cloud API dependency and cost volatility; (6) Architect AI usage in tiers, reserving costly cloud models for complex cases with human approval; (7) Define clear policies on actions when token limits are reached to avoid silent failures.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.kaspersky.com/blog/tokenomics-ai-and-cybersecurity/56523/","fetched":true,"fetchedAt":"2026-10-07T19:20:32.811Z","wordCount":1666}
Threat ID: 6ac69b802cdf04f65675cecc
Added to database: 10/07/2026, 19:20:32 UTC
Last enriched: 10/07/2026, 19:20:40 UTC
Last updated: 10/08/2026, 01:19:23 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.