Credential stuffing

Last verified

Credential stuffing replays leaked credentials in bulk. For AI APIs the version that matters is simpler than the password case: harvested keys are tested against provider endpoints, and the ones that still authenticate are used or resold.

The relevant consequence is that a key which leaked months ago and was never rotated is still being tested. Exposure does not expire, and neither does the attacker's copy.

Rotate anything that was ever exposed, however long ago and however briefly.