LLMjacking

First described by Sysdig researchers, LLMjacking targets the growing number of AI API keys and cloud accounts with model access. Victims can face large bills and reputational risk from content generated in their name.

LLMjacking typically involves:

  • Credential theft: Stealing cloud or AI API keys from code, logs, or infected devices.
  • Access validation: Checking which models and quotas the keys unlock.
  • Resale: Selling access through reverse proxies.
  • Abuse: Generating content, running agents, or supporting other attacks.
  • Cost exposure: Running up large usage charges for the victim.

More recent reporting describes stolen AI compute being used as infrastructure for offensive tooling, raising the stakes beyond financial loss.

Defenses include protecting and rotating keys, limiting model access by account, setting budgets and alerts, and monitoring for unusual usage.

How PointGuard AI Helps

PointGuard AI AI Security Posture Management identifies exposed keys and risky AI service configurations, and AI Discovery inventories AI services and credentials in use, helping teams detect and close LLMjacking paths.

Learn More

Watch Blog Video

Follow us on LikedIn

Our Newsletter

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.