Urgent.News

What's breaking now, across thousands of outlets.

Tech

LLMjacking and the Hidden Cost of a Stolen API Key

For the past few years, one topic has constantly been on the minds of tech professionals around the world: AI. AI is no longer just another piece of the tech stack but is fast becoming its foundation. Major business features, like customer support and data analysis pipelines, are being shifted to Large Language Models ( LLMs ), and businesses are more dependent on LLMs every day. That dependency…

LLMjacking refers to the unauthorized access to a Large Language Model (LLM), which has become a valuable target for attackers as these models are increasingly integrated into core business processes. Unlike traditional attacks targeting AWS or GCP access keys, LLMjacking can cause more significant harm financially and to an organization's reputation.

The potential financial impact of LLMjacking arises from the expensive nature of LLM usage, with attackers potentially abusing it to generate spam emails, phishing websites, and malware. Additionally, if a compromised LLM credential provides access to custom models, internal prompts, or sensitive data pipelines, attackers could gain knowledge about the organization's inner workings, enabling them to extend their foothold, sell the information on the dark web, or manipulate the model to provide misleading or biased responses.

Common attack vectors include phishing campaigns, misconfigured environments, and exposed client-side code. Phishing is a particularly effective method, often relying on social engineering tactics like urgency or spoofing platform notifications to trick users into revealing their credentials. Misconfigured cloud environments and overly permissive S3 buckets, Kubernetes dashboards, or Git repositories also provide attackers with the necessary access without the need for exploiting vulnerabilities directly.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

What If the Developer Internet Had a TV? 📺

What If the Developer Internet Had a TV? 📺 The developer internet moves constantly. New projects appear. AI models are released. Frameworks change. Security issues surface. Research gets published.

  • DEV·TV presents developer information like a TV broadcast.
  • Streams include GitHub, Hacker News, DEV, Hugging Face, security feeds.
  • Aim is to highlight compelling moments, not all content.

Crowdwide is ALMOST DONE!! WOOOHOOO!! 🎉🚀

So… after weeks of building, fixing, breaking, fixing again, questioning my life choices, and repeating the same cycle… Crowdwide is almost done!!

  • Crowdwide platform nearing stable release
  • Community Map feature highlights platform activity
  • Developer overcame API key and map feature challenges

AgentRisk: A Pay-Per-Call Risk Oracle for Autonomous Trading Agents

The problem AI trading agents on Base are increasingly autonomous — they see a token, decide, and execute, often with no human in the loop.

  • AgentRisk provides machine-readable risk assessments for autonomous trading agents on Base.
  • Offers signed, cacheable verdicts with detailed attestation including risk score and timestamp.

More from Friday 2 October →