LLMjacking

Last verified

LLMjacking is the theft of AI API credentials for the purpose of using or reselling model access at the owner's expense — the LLM-era analogue of cryptojacking.

It is automated and continuous. Scanners watch public repositories, pastebins, client bundles and mobile app traffic. A 2026 study found 282 iOS apps leaking LLM API keys.

The economics favour the attacker: their cost is zero, yours is metered and charged to a saved card. LLMjacking: how AI key theft works.