logo

LLM Hijackers Quickly Incorporate DeepSeek API Keys

ID: cbfdd583-91a0-5911-9879-d32813d706b1

STIX ID: report--cbfdd583-91a0-5911-9879-d32813d706b1

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-02-07

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers observed widespread "LLMjacking" operations in which attackers obtain stolen API keys and cloud credentials to proxy access to commercial LLMs (e.g., DeepSeek), deploy OAI reverse proxies (ORPs) with obfuscation and Cloudflare tunnels, and spread usage across many accounts to evade detection; incidents have caused significant unexpected billing (examples include personal AWS accounts incurring $10k–$20k in hours) and rapid abuse of newly released models shortly after their launch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.