Stolen AI API tokens reach a reselling proxy within minutes, Unit 42 documents the 'transfer station' market and the account-takeover variant that mints its own keys
An exposed AI API key is a billing incident on a clock: Unit 42 saw one reach a reseller in minutes and run up nearly a million dollars
Defender actions
- Set hard spend ceilings on AI-provider accounts that the consuming credential cannot itself raise, and scope each API token to the minimum model and quota it needs; the account-takeover variant in this report works by removing billing limits and disabling usage alerts with the same account that spends the budget.
- Treat an AI API token found in a code repository or an unsecured file share as a same-shift rotation, not a backlog ticket: Unit 42 observed resale inside minutes of exposure.
Analysis
Unit 42 has put a name and a market structure to something most organisations still treat as a billing anomaly. "Token jacking" is the theft of AI-provider API tokens (through infostealer malware, phishing, credentials leaked in poisoned packages, or keys sitting in what Unit 42 calls improperly secured file shares or code repositories) and the monetisation path is a gray-market reseller layer Unit 42 calls a transfer station (Palo Alto Networks Unit 42, 2026-08-06). These services are typically built on openly available LLM-proxy software, which is doing something specific for the operator: it sits in front of the stolen legitimate token, obfuscates the real credential from the paying customer, handles authentication rotation and billing, and resells discounted access to the underlying model. The buyer never sees whose key they are spending, and the victim sees only usage.
The speed is what changes the response. "We’ve responded to cases where attackers stole inadvertently exposed credentials and integrated them into a transfer station within minutes" (Palo Alto Networks Unit 42, 2026-08-06), and in one such case "this led to nearly a million dollars in charges before discovery and containment" (Palo Alto Networks Unit 42, 2026-08-06). Unit 42 also documents a variant that does not depend on a single leaked key, and it is account takeover rather than a rogue employee: the privileged corporate developer accounts in question are harvested by infostealers or phishing, or bought from access brokers on dark-web marketplaces. An attacker holding one uses that account's own privileges to mint new API keys, provision additional models, remove billing limits, and disable usage alerts and logging, extending the abuse window by dismantling the controls that would have ended it. The financial exposure is largely one-way: "Organizations impacted by token jacking have very little recourse to recover funds billed by the AI services for using their API tokens" (Palo Alto Networks Unit 42, 2026-08-06).
Cited evidence
We’ve responded to cases where attackers stole inadvertently exposed credentials and integrated them into a transfer station within minutes.
This led to nearly a million dollars in charges before discovery and containment.
Organizations impacted by token jacking have very little recourse to recover funds billed by the AI services for using their API tokens.
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.