LLMjacking: How hackers steal your AI API keys and stick you with the bill

AI tools can turn a team of three developers into a fully functioning company. They can also push that company to the brink of bankruptcy.

On this week’s Security Intelligence, we talk LLMjacking: Hackers steal your AI API keys and then rack up massive bills, even blowing past usage caps in some cases. One small startup saw its typical bill balloon from $180 a month to $82,000 in two days. We chat about what makes AI API keys vulnerable and how we can tighten our defenses to keep these vital credentials safe. Then we get into how AI is transforming adversary simulation and red teaming, and why the human is still the most important part of the loop. Finally, CISA is considering cutting the federal patch window from two weeks to three days. Can we actually move that fast?

Segments:

  • 00:00 – Intro
  • 1:15 – What is LLMjacking?
  • 12:29 – AI and adversary simulations
  • 22:09 –  Can we patch faster?

The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity.

Subscribe now on your favorite platform YouTube Spotify Apple Podcasts

Take the next step in your cybersecurity journey

IBM Guardium

Secure critical enterprise data from both current and emerging risks, wherever it lives.

Explore IBM Guardium
Data security and protection solutions

Protect enterprise data across its lifecycle and simplify compliance requirements               

Explore security solutions
The 2026 Guide to Cybersecurity

Explore every facet of cybersecurity, from basic principles and attack types to cutting-edge tools and developing cyberthreats.  

Learn more about cybersecurity
Take the next step!

Become an expert in all things cybersecurity and tech with IBM

  1. Subscribe to the Think newsletter
  2. Explore The 2026 Guide to Cybersecurity