LLMjacking can run up your business’ AI bill fast – how to stop it
Security experts, notably Google Threat Intelligence Group's John Hultquist, have identified a significant surge in "LLMjacking" throughout 2026, an illicit practice akin to cryptojacking. This trend involves cybercriminals stealing and misusing AI computing power and resources belonging to businesses. A burgeoning underground market facilitates the trade of compromised AI account credentials and API keys, enabling unauthorized access to high-capacity AI models from providers like OpenAI and Anthropic.
LLMjacking exploits stolen credentials or API keys, often acquired through phishing, data breaches, or network vulnerabilities, to gain unauthorized access to business AI accounts. These compromised accounts typically offer high usage limits, leading to substantial token overspill charges for victims, with Sysdig estimating daily costs potentially exceeding $100,000. Criminals leverage this stolen access for resource-intensive tasks, running their own malicious AI models, data exfiltration, or even poisoning training datasets, while also gaining an economic advantage by accessing AI models at discounts up to 97%.
For the OpenClaw ecosystem, LLMjacking poses a direct threat to the integrity and cost-efficiency of agentic AI frameworks and multi-agent systems. Agent developers must recognize that compromised API keys or credentials can lead to unauthorized agent operations, resource depletion, and sensitive data exposure within their deployments. This necessitates