LLMjacking Chaos: DeepSeek’s Costly Cloud Invasion Uncovered!
LLMjacking attacks target DeepSeek, resulting in massive cloud bills. Sysdig uncovers a bustling black market for LLM access, where ORP operators offer unauthorized entry to hijacked accounts. Learn how these cunning attackers steal and profit from LLM usage, turning free rides on the cloud into a costly affair for victims.

Hot Take:
Looks like the only thing getting “jacked” faster than LLMs these days is the price of avocados! With LLMjacking attacks targeting DeepSeek, it seems even AI models aren’t safe from the clutches of cybercriminals. Maybe it’s time we start encrypting our cyber-pickles!
Key Points:
- LLMjacking attacks on the rise: New targets include DeepSeek models.
- Cybercriminals exploit API keys to dodge hefty cloud LLM costs.
- LLM access sold on a black market, with ORPs offering unauthorized entry.
- Over two billion tokens consumed by these attacks, costing victims dearly.
- Securing credentials and monitoring suspicious activity are essential countermeasures.
Already a member? Log in here