Google Threat Intelligence Group finds dark web marketplaces selling access to AI models, including from Anthropic, Google, and OpenAI, at up to 97% discounts
Security researchers warn of surge in ‘LLM-jacking’ attacks targeting companies' costly AI resources
Context & Ripple Effects
The trade in illicit model access builds on OpenAI credentials found in stealer logs in 2023, showing that attackers have treated generative-AI accounts as a monetizable asset rather than merely a target for data theft.
It also broadens the security stakes around model access: Google Threat Intelligence Group had already documented hackers using AI in zero-day exploitation, while the reported LLM-jacking activity targets the costly underlying resources companies pay to use.
First-order effects
- Anthropic, Google, and OpenAI face immediate account-abuse and revenue-leakage exposure as access to their models is resold through dark-web marketplaces at steep discounts.
- Companies funding AI workloads become targets for LLM-jacking, putting their model-access credentials, usage limits, and AI budgets directly at risk.
Second-order effects
- AI providers will need to tighten authentication, usage monitoring, and abuse controls, increasing friction for legitimate customers whose access patterns resemble bulk or automated use.
- The illicit market compounds the pricing pressure already created by buyers seeking cheaper model alternatives, because unauthorized access creates a zero-authorized-cost substitute without provider support or contractual safeguards.
Third-order effects
- If LLM-jacking persists, frontier-model access is likely to be managed less like a simple software subscription and more like a high-value security entitlement, with controls becoming part of product differentiation.
- The pattern links cybercrime economics to AI distribution: providers that can secure access while keeping legitimate deployment workable gain an advantage over rivals whose access can be more easily diverted.
The trend: AI model access is becoming a contested distribution layer, where cost pressure and cybercrime both push providers to treat usage credentials and compute allocation as security-critical assets.