API key theft
Stealing the keys or login sessions needed to call AI services, turning someone else's quota, data, and identity into your own attack resources.
Definition
Once a key leaves official channels, it can be resold and rotated until the quota runs out.
Keys in evaluation sandboxes, wrapper services, and local clients are not the same boundary as the lab's own systems.
{esc(t(CURRENT_LANG, "not_confused_with"))}
- Not stolen model weights.
- Not official discount promotions.