Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Cybercriminals are exploiting API keys used by developers to access AI platforms through a technique called token jacking. Attackers steal these authentication tokens to gain unauthorized access to expensive AI resources, which they either use themselves or resell through gray-market services called transfer stations. These transfer stations act as intermediaries, offering frontier AI model access at discounted rates using stolen credentials. The financial impact can be catastrophic, with victims potentially losing hundreds of thousands to millions of dollars before detection due to unlimited scaling defaults and cyclical billing. Attackers obtain tokens through information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages. Organizations can mitigate risks through spending limits, privileged account reviews, short-term bearer tokens, AI gateways, and tight development environment management.
Indicators of Compromise
- ip: 38.46.219.162
- ip: 116.105.166.148
- ip: 38.46.219.166
- ip: 38.46.219.163
- ip: 23.237.196.170
- ip: 198.255.70.210
- ip: 117.72.74.48
- domain: amutes.com
- domain: abb1.life
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Description
Cybercriminals are exploiting API keys used by developers to access AI platforms through a technique called token jacking. Attackers steal these authentication tokens to gain unauthorized access to expensive AI resources, which they either use themselves or resell through gray-market services called transfer stations. These transfer stations act as intermediaries, offering frontier AI model access at discounted rates using stolen credentials. The financial impact can be catastrophic, with victims potentially losing hundreds of thousands to millions of dollars before detection due to unlimited scaling defaults and cyclical billing. Attackers obtain tokens through information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages. Organizations can mitigate risks through spending limits, privileged account reviews, short-term bearer tokens, AI gateways, and tight development environment management.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/ai-token-jacking"]
- Adversary
- null
- Pulse Id
- 6a748055b6dd0f782e3470ff
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip38.46.219.162 | — | |
ip116.105.166.148 | — | |
ip38.46.219.166 | — | |
ip38.46.219.163 | — | |
ip23.237.196.170 | — | |
ip198.255.70.210 | — | |
ip117.72.74.48 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainamutes.com | — | |
domainabb1.life | — |
Threat ID: 6a74b929bf8831d539fc6e58
Added to database: 08/06/2026, 16:41:13 UTC
Last updated: 08/06/2026, 21:08:25 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.