Skip to main content

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

0
Medium
Published: 08/06/2026 (08/06/2026, 12:38:45 UTC)
Source: AlienVault OTX General

Description

Cybercriminals are exploiting API keys used by developers to access AI platforms through a technique called token jacking. Attackers steal these authentication tokens to gain unauthorized access to expensive AI resources, which they either use themselves or resell through gray-market services called transfer stations. These transfer stations act as intermediaries, offering frontier AI model access at discounted rates using stolen credentials. The financial impact can be catastrophic, with victims potentially losing hundreds of thousands to millions of dollars before detection due to unlimited scaling defaults and cyclical billing. Attackers obtain tokens through information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages. Organizations can mitigate risks through spending limits, privileged account reviews, short-term bearer tokens, AI gateways, and tight development environment management.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 23:02:41 UTC

Technical Analysis

Cybercriminals exploit API keys (authentication tokens) used by developers to access AI platforms through a technique called token jacking. By stealing these tokens via information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages, attackers gain unauthorized access to expensive AI resources. These resources are either consumed by the attackers or resold through intermediary gray-market services known as transfer stations, which offer discounted access to frontier AI models using stolen credentials. The financial impact on victims can be catastrophic, with losses potentially reaching hundreds of thousands to millions of dollars before detection, due to default unlimited scaling and cyclical billing models. Mitigation strategies include enforcing spending limits, conducting privileged account reviews, using short-lived bearer tokens, deploying AI gateways to control access, and maintaining strict controls over development environments.

Potential Impact

Unauthorized use of AI platform resources through stolen API tokens can lead to significant financial losses for organizations, potentially in the hundreds of thousands to millions of dollars. The exploitation leverages default unlimited scaling and cyclical billing, allowing attackers to incur large charges before detection. Additionally, stolen tokens are monetized in gray-market transfer stations, facilitating broader abuse of AI services. The compromise vectors include credential theft via malware, phishing, supply chain attacks (e.g., poisoned npm packages), and compromised code repositories.

Defensive Guidance

There is no direct patch for token jacking as it exploits stolen credentials rather than a software vulnerability. Organizations should implement spending limits on AI resource usage to prevent runaway costs. Privileged account reviews should be conducted regularly to detect unauthorized token usage. Use short-term bearer tokens to limit the window of token misuse. Deploy AI gateways or access control mechanisms to monitor and restrict API usage. Maintain strict management and security of development environments to reduce the risk of token theft. These mitigations align with vendor and industry recommendations for protecting API keys and managing AI platform access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/ai-token-jacking"]
Pulse Id
6a748055b6dd0f782e3470ff

Indicators of Compromise

Ip

ValueDescriptionCopy
ip38.46.219.162
ip116.105.166.148
ip38.46.219.166
ip38.46.219.163
ip23.237.196.170
ip198.255.70.210
ip117.72.74.48

Domain

ValueDescriptionCopy
domainamutes.com
domainabb1.life

Threat ID: 6a74b929bf8831d539fc6e58

Added to database: 08/06/2026, 16:41:13 UTC

Last enriched: 08/07/2026, 23:02:41 UTC

Last updated: 09/20/2026, 06:26:10 UTC

Views: 93

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses