Hackers Are Targeting AI Servers to Steal API Keys and Install Crypto Miners
Brief
Threat actors are increasingly targeting exposed AI infrastructure to steal model-provider API keys , abuse cloud-connected services, and deploy Monero cryptominers, according to new research from Wiz Threat Research.
Wiz monitored honeypots designed to imitate commonly deployed AI and machine-learning services for 90 days, including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, Ollama, and other platforms.
The researchers found attackers adapting their tools and post-exploitation activity to the internals of individual AI services.
The activity shows that AI infrastructure is becoming a valuable cloud attack surface. These platforms often hold high-value credentials, connect to internal tools, process untrusted input, and may have permissions to access cloud services.
A compromised AI proxy can potentially expose keys for providers such as OpenAI, Anthropic, Azure, and Gemini.
