Unit 42
Read post

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Cybercriminals are stealing AI API keys (tokens) from developers and organizations to fuel gray-market 'transfer stations' — proxy services that resell AI compute capacity at steep discounts. Attackers harvest keys via info-stealers, phishing, exposed code repositories, and poisoned npm supply chain packages. Once stolen, keys are integrated into transfer station platforms (often running open-source proxies like new-api or one-api) within minutes, generating hundreds of thousands to nearly a million dollars in API charges before victims notice. Mitigations include spending limits with anomaly alerts, short-lived bearer tokens instead of long-term keys, AI gateways, network boundaries for compute resources, and tight control of development package pipelines.

    #security#cyber#llm#npm
Today•10m read time•From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryHow Tokens WorkTransfer StationsHow Transfer Stations Obtain TokensImpact of Transfer Stations' Token JackingMitigationConclusionIndicators of CompromiseAdditional Resources
76 Impressions
Unit 42's image
Unit 42

Unit42 is a cybersecurity research team known for its analysis of cyber threats, malware, and cyber...

63 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard