API key theft

Stealing the keys or login sessions needed to call AI services, turning someone else's quota, data, and identity into your own attack resources.

Definition

Once a key leaves official channels, it can be resold and rotated until the quota runs out.

Keys in evaluation sandboxes, wrapper services, and local clients are not the same boundary as the lab's own systems.

{esc(t(CURRENT_LANG, "not_confused_with"))}

{esc(t(CURRENT_LANG, "example"))}

Fake reseller case and supply chain case.

{esc(t(CURRENT_LANG, "related_terms"))}

{esc(t(CURRENT_LANG, "sources"))}