LLM-Jacking: Inside the Dark-Web Market for Stolen AI

LLM-Jacking: Inside the Dark-Web Market for Stolen AI

LLM-Jacking: The Dark-Web Economy in Stolen AI

Stolen access to frontier AI models is now sold on dark-web marketplaces at discounts of up to 97 percent. That figure comes from Google’s Threat Intelligence Group. Principal analyst John Hultquist told the Financial Times that a “burgeoning economy centered on AI access” has formed underground. Premium ChatGPT and Claude subscriptions run to roughly $200 per user per month. On criminal forums, stolen equivalents sell for pocket change, sometimes with a replacement guarantee if the provider bans the account.

This activity now has a name, a history and a supply chain. Security researchers call it LLM-jacking, and in the past year it has graduated from novelty to infrastructure.

Where LLM-Jacking Came From

Sysdig’s Threat Research Team coined the term in May 2024. The first observed attack used credentials stolen through a Laravel vulnerability to reach cloud-hosted models. The attacker resold access through reverse proxies while the account owner paid the bill. Sysdig estimated a worst case of over $46,000 per day in consumption costs for a Claude 2.x quota owner. Ten AI platforms were targeted with the same credential-checking script.

The threat then industrialised. In February 2026, Sysdig and Pillar Security documented “Operation Bizarre Bazaar.” Their honeypots captured 35,000 attack sessions between December 2025 and January 2026, at an average of 972 per day.

The campaign’s storefront, a gateway called silver.inc, resold stolen inference at 40 to 60 percent below retail. It offered more than 30 model providers through one interface. Google’s researchers also report that average prices for stolen AI accounts more than doubled in 2026. Demand is concentrating on Claude and Gemini credentials, plus coding tools such as Cursor Pro and Devin.

Two Currencies: Accounts and Compute

The underground trades two distinct products. Credentials come first: stolen subscriptions, API keys and session tokens resold to buyers who want premium models cheaply. Compute hijacking comes second: attackers compromise cloud accounts and run AI workloads on the victim’s GPUs.

Google documented both forms in its September 2026 threat tracker, “From Prompting to Autonomy.” In one April intrusion, an attacker used an exposed GitHub token to enter a company’s cloud account. The attacker then enabled Gemini Enterprise and requested additional Nvidia GPUs. In other cases, a China-linked group tracked as UNC6508 deployed open-weight models inside compromised academic and medical research environments. Running models locally keeps the prompting away from commercial API monitoring entirely.

How the Credentials Get Stolen

Most stolen keys are never taken from AI providers at all. Anthropic’s September 2026 threat report is blunt on this point. In every case it investigated, the keys came from customers’ own environments. Anthropic’s own systems were not compromised. Google’s Cloud Threat Horizons report found identity compromise underpinned 83 percent of cloud and SaaS intrusions in the second half of 2025.

The theft methods are ordinary and effective. Infostealer families including LummaC2, StealC, Vidar and ACR Stealer now harvest the configuration files of AI coding tools. ACR Stealer went after the plaintext API keys stored by Cline and Continue in May 2026. One criminal group linked to ShinyHunters mass-downloaded 1.8 million Android apps, decompiled them, and scanned for hardcoded secrets. Attackers also scan public repositories, container images, build logs and package registries.

The developer workstation is the crown jewel. Google’s report describes malware that planted files in the hidden directories AI coding tools read, including.claude,.vscode and.cursor. The group behind it, UNC6780 or TeamPCP, published trojanised copies of popular MCP servers. It also injected code into legitimate GitHub repositories.

Some payloads carried prompt injections written as extreme weapons requests. The goal was to make LLM security scanners refuse the file and skip the malware beneath.

What Criminals Do With Stolen AI

The most consequential case in Google’s report compressed a campaign into hours. In the second quarter of 2026, a financially motivated actor compromised a cloud resource. Using an AI coding chatbot, a prompt and agent instructions, the actor built a credential-harvesting operation in under six hours. The AI managed the scanning pipeline, troubleshot its own errors and rotated IP addresses without human intervention. It compromised thousands of third-party credentials.

Anthropic’s report describes the same shift, calling it AI applied with “living off the land” logic. A Russian-speaking group stole keys from an AI vendor’s sandbox and attacked roughly thirty AI companies in four days. A French-speaking hacktivist ran a month-long campaign entirely on stolen keys. One operator dumped 2,100 Azure AD token sets across more than 40 corporate tenants in about 34 hours. In one case, AI agents rebuilt malware in a loop until it stopped triggering security products.

Distillation is the state-scale variant. Anthropic attributed 151 million exchanges between May and July 2026 to operators linked to Alibaba. Volume peaked at nearly three million per day from more than 3,500 fraudulent accounts. It accused Moonshot of relaying nearly 300,000 customer requests through Claude over ten days. It separately attributed 12.1 million exchanges in fourteen days to DeepSeek.

US agencies including the NSA and FBI named several of these labs in a joint advisory.

The Economics Favour the Attacker

Hultquist’s warning is about asymmetric costs. Attackers acquire expensive AI tokens at a small fraction of list price. Defenders pay full freight for detection, response and cloud overages. The Cloud Security Alliance assesses the six-hour campaign could finish faster than many organisations detect a cloud intrusion. That comparison is its own assessment, not Google’s.

One caveat belongs in every headline about this economy. The 97 percent figure describes seller listings, not verified transactions. Some listings are scams, hijacked multi-user accounts or dead credentials. The trend direction — more buyers, more sellers, rising prices — is the signal, not any single discount.

LLM-Jacking: Inside the Dark-Web Market for Stolen AI

What Defenders Should Actually Do

The guidance converges from every report. Treat AI keys and agent integrations with the same seriousness as production credentials, because attackers do. Keep an inventory of AI subscriptions, API keys, model endpoints and GPU instances, with named owners. Scope keys narrowly, set spending limits, and prefer short-lived credentials over long-lived service-account keys. Scan repositories, mobile packages and container layers for secrets before attackers do.

Monitor behaviour, not just billing. An attacker keeping usage below a financial threshold is invisible to cost alerts alone. Correlate identity, source IP, model, prompt volume and GPU utilisation. A rarely used service account launching GPU workloads that pull unfamiliar model images warrants a high-risk alert. Organisations early in AI adoption lack baselines, which makes unusual growth easy to mistake for experimentation.

Editor’s Note: This article was independently reported and verified by TechRecast. Primary sources include Google Threat Intelligence Group’s “From Prompting to Autonomy” report of September 8, 2026, and Anthropic’s “Detecting and countering misuse of AI” report of September 10, 2026. Google’s Cloud Threat Horizons Report H1 2026, Sysdig’s original LLMjacking research of May 2024, and the February 2026 Operation Bizarre Bazaar findings by Sysdig and Pillar Security were also used. A Financial Times interview with GTIG’s John Hultquist, published September 27, 2026, anchors the market-pricing figures. Corroborating coverage from Reuters, SiliconANGLE, the Cloud Security Alliance and specialist security publications informed the analysis.

The 97 percent discount figure, seller volumes and price trends are drawn from marketplace listings monitored by Google. They have not been independently verified as completed transactions. TechRecast contacted no parties for comment before publication.