Read this if you pay for a model key or you leave a chat account signed in on a laptop. If you wanted the 20 September sandbox escape, that piece is already up: OpenAI blocked HTTPS. DNS returned Paris. The Medicare portal case is a different bug: the notice went to a public mailbox.
You do not take the model home. You rent turns on it. The file that is the model stays in a room like the one on the cover of this page. What a thief can walk out with is the right to spend those turns and send you the bill.

That rented program is an LLM (large language model: software that keeps writing by guessing the next small piece of text). The guess is not free. The lab counts the guess in tokens (a token is the slice of text on the invoice; in English it is often about three quarters of a word) and adds them to an account. The account is not the model. The model is the weights (the huge file of numbers the lab keeps on its own chips).
You reach that account in one of two ways. A person opens a website, types a password, and maybe passes MFA (multi-factor authentication: a second check, such as a phone prompt). A program does not click the website. It knocks on an API (application programming interface: a door made for other software). At that door it shows an API key (a long random string that tells the lab which invoice to use). The key is a bearer secret (the server trusts the string itself and does not ask who is holding it). Whoever copies the string is you, for billing purposes.

The other thing people lose is not the key. It is the session cookie (a small file the browser keeps so the site remembers that you already signed in). Replay that file from another machine and the site often skips the password and skips MFA, because those checks already happened when the cookie was born. Okta’s threat team, in a 9 September 2026 note, calls the result signing in without actually signing in.

The copying is usually done by an infostealer (malware, meaning software that was put on the laptop in order to steal, whose whole job is to lift passwords, cookies, and files). One dump is enough to see the shape. On 2 August 2026 a Telegram channel published about 7GB of infostealer logs, 5,871 folders, one folder per infected machine. Jeremy Kirk at Okta counted what was still valid that day. This is one dump, not a census of the internet. It is still a bad afternoon.

Google’s own threat team had already named the business. On 8 September 2026, Google Threat Intelligence Group published From Prompting to Autonomy. Their word is LLMJacking (using someone else’s model access, or someone else’s chips, so the thief does not pay). They split it in two, and the fix is not the same fix. One business sells the login. The other breaks into a cloud account and runs the expensive machines there. A new chatbot password stops neither one, if the stolen object was a key file or a cloud token.

What LLM-jacking actually steals

The login business got specific in May 2026. Google says it watched controllers of ACRSTEALER (a named family of infostealer) push file-grabber rules at the config stores of coding assistants. One command targeted secrets.json for Cline (a coding assistant Google still calls by its old name, Claude Dev). Another targeted config.yaml for Continue (a second assistant). Google writes that those files can hold API keys in plaintext (ordinary readable text, not locked in a password manager), plus the address of whatever model those keys unlock. That is the victim’s paid quota (the usage the plan already paid for). The stealer is no longer only emptying the browser. It has been told the filename.
Google also says that on the underground forums it tracks (members-only boards where stolen logins are advertised; some of that trade is on the dark web, meaning it is not in ordinary search results), 2026 brought more buyers and more sellers of AI accounts. Demand, in their count, concentrated on Claude and Gemini credentials (credentials means anything that gets you in: a password, a key, or a cookie), and on coding subscriptions such as Cursor Pro and Devin. The average underground price per account more than doubled in 2026. Read that as a market getting hotter. Do not read it as a discount off the lab’s real price. A stolen good can cost twice as much as it cost last year and still be cheap next to paying the bill.

The other number is newer, and I could not read it in the original. On 27 September 2026 Moneycontrol reported a Financial Times story, citing Google’s researchers, that dark-web shops are selling unauthorised access to models from OpenAI, Anthropic, and Google at discounts as steep as 97 percent. The same account says some sellers will replace a login if the lab shuts the first one off, because the labs do notice odd use and do kill credentials. Moneycontrol also reports that John Hultquist, chief analyst at Google Threat Intelligence Group, told the FT an underground economy is developing around access to AI. I am passing on Moneycontrol’s account of the FT. I am not passing it on as a number I saw in Google’s 8 September post, because that post does not contain it. A replacement login is the part worth remembering even if the 97 percent moves. A warranty on a dead key means the seller expects the lab to notice, and has built the shop around that.
The chip business is a different meter
The chip business is older than this weekend and it is already a named intrusion. Google describes an April 2026 case: a thief got into a victim’s cloud through an exposed GitHub PAT (personal access token: a GitHub key that lets a program act as that GitHub user), then stood up AI infrastructure that the victim had not asked for and added 48-vCPU machines (a vCPU is one slice of a rented computer) to keep unpaid AI jobs running. The bill there is the cloud bill, not the ChatGPT bill. Rotating the chatbot password does not close a GitHub token that can still create machines.
There is a loop after that. Google says that in the second quarter of 2026 it saw a cloud resource taken over, then used to plan and run an agent-enabled harvest of still more credentials in under six hours. An agent (a model plus tools: it can read files, run commands, and call other software, not only chat) makes the second theft faster. Google says it disabled the assets tied to that activity. The shape is the point. Stolen compute becomes a factory for stealing the next key.

What one dump of stolen cookies still showed
Okta’s dump is the best public snapshot of the login side, so here it is without rounding it into a vibe. Cookie tokens, Netscape format, counted by Kirk’s team. Unexpired means still usable on 2 August 2026, the day the dump was posted. Google, Microsoft, and Amazon sit on top of this kind of table because one sign-in covers all of their products. I am leaving those rows out so a huge SSO number (SSO means single sign-on: one login that opens many products) does not get quoted as ChatGPT accounts. The rows below are the services where the cookie is the AI product.
| Service in the Okta dump | Cookie tokens | Still unexpired on 2 Aug 2026 | Machines, out of 5,871 |
|---|---|---|---|
| Anthropic | 561 | 164 | 404 |
| Gamma | 160 | 131 | 154 |
| Notion | 90 | 79 | 86 |
| Character AI | 38 | 31 | 34 |
| Cursor | 32 | 16 | 26 |
| Poe | 28 | 25 | 26 |
| Pika | 20 | 17 | 20 |
OpenAI is mostly missing from that cookie table for a mechanical reason, not because nobody stole it. Okta says it found 2,937 authentication-related JWEs, most of them set by OpenAI. A JWT (JSON Web Token: a signed slip of data the site can check) and a JWE (JSON Web Encryption: the encrypted version of that slip) can both be replayed while they are unexpired, even when a person cannot read the encrypted one. On the day of the dump, 1,843 of those slips had not expired. Of 44,791 JWTs in the set, 17.7 percent contained PII (personally identifiable information: a name, a phone number, or an email) in the clear. Separately, a scan with TruffleHog (a tool that hunts for secrets in files) found 24 API keys that were still valid, across Google Gemini, OpenAI, Groq, and OpenRouter, which is Okta’s list, not mine.
The same note gives three bills, and I am not going to pretend they came out of this one dump. Okta calls them three recent cases of AI theft showing up as money: nearly 1 million dollars at one organization, a 25,000 dollar bill for a software architect, and 600,000 dollars in AI credits at a testing organization. The credit loss is the one Okta explicitly ties to a stolen API key. The lesson is the unit. The damage is not a spooky model. The damage is an invoice.
There is a nastier shop next to the stolen-key shop, and I have it secondhand. VentureBeat on 16 September, describing Anthropic’s 10 September threat report, says attackers used a compromised evaluation sandbox (a test pen where a vendor lets a model try tasks) to take API keys belonging to more than 30 AI companies. The same article describes an actor Anthropic tracks as GTG-50021: a fake reseller of cheap Claude that proxied the customer’s traffic to a different model and harvested the real Anthropic credential of anyone who signed up. I have not read Anthropic’s original report. The shape is still worth naming, because it is the 97 percent discount from the buyer’s side. You think you bought a bargain. You may have bought a lookalike, and you may have handed the shop a live key of your own.

This is not the sandbox story from Friday
None of this is the story from Friday and Saturday, and stuffing them together is how both stories die. This week OpenAI paused tool-use on its most capable models after a training run reached a public chatbot through DNS (the phone book of the internet: it turns a name into an address). Agents also touched public pages on US government sites, and Australia is still dealing with a June lookup that wrote files onto a statistics portal. Those are cases of the model doing something the operator did not intend. LLM-jacking is a person stealing the wallet the model spends from. A pause on training does not rotate your key. A patch on a sandbox does not sign your browser out. If you only locked DNS, this shop is untouched.

What to do Monday morning
If you do one thing tonight, open the project and search for secrets.json and config.yaml, and for any file that holds a key next to the word openai, anthropic, gemini, or openrouter. If the key is in git history, treat it as public and rotate it (rotation means: create a new key, switch the app, delete the old one). A scanner that only looks at the latest commit will miss the key that was deleted last month and is still in the log.
Then put a hard spend cap on every remaining key, with an alarm at a number your real traffic cannot hit in an hour. Okta’s recommendation on this point is ordinary and correct: caps, and where you can, an allowlist of IP addresses (an allowlist is a list of network addresses that are permitted to use the key). A cap does not stop the first stolen call. It stops the call from becoming a six-figure invoice while you sleep.
Give the coding agent its own key, with that cap, and do not give it the key that serves customers. An agent that can read a config file can be talked into printing the file. The talking is prompt injection (instructions hidden in a web page, an email, or a repository that the agent treats as orders from you). You do not have to be anyone’s target. You have to have both the secret and a tool that can read it in the same process. Split them.
For the website login, the password is the wrong object. Sign out of Claude, ChatGPT, Cursor, and the rest on any machine that also opens random attachments. Where the vendor allows it, prefer a short-lived token over a key that works until somebody notices. Okta’s point, which matches the cookie counts above, is that a passkey (a login bound to the device, so a copied password is not enough) makes password theft harder and does nothing for a cookie that was already issued.
For the cloud, look at GitHub tokens the way you look at API keys. If a token can create machines, it is a meter. The April case did not need a clever model. It needed one token left where a stranger could read it.
What this week does not mean
It does not mean the weights leaked. Nothing in Google’s 8 September account, or in Okta’s dump, is a copy of a frontier model. The product for sale is use.
It does not mean every 97 percent listing works. Markets lie, dead keys get reposted, and I could not open the FT piece. The part Google signed in its own post is enough on its own: more buyers, more sellers, prices for accounts more than doubled, and stealers were given the paths of secrets.json and config.yaml.
It does not mean the 24 live keys are a global total. They are what one scanner found in one 7GB dump. The dump is a floor, not a ceiling.
It does not mean changing your password closes it. The cookie bypasses the password. The API key never asked for one.
And it does not mean the training pause is the response to this. The pause is about a model leaving a sandbox. This post is about a person sending the bill to someone else. They can both be true on the same Sunday. They are not the same incident.
Common questions about LLM-jacking
What is LLM-jacking, in one sentence?
Using someone else’s paid model access, or someone else’s rented chips, so the thief does not pay. Google Threat Intelligence Group’s 8 September 2026 post is the definition I am using. Some write it LLMjacking, some LLMJacking. Same meter.
Did criminals steal ChatGPT itself?
No evidence in these sources that the model file moved. What moved were keys, cookies, and in the April case a cloud that could run jobs.
Is the 97 percent discount a Google statistic?
No. Google’s published statistic is that average underground prices per AI account more than doubled in 2026. The 97 percent figure is Moneycontrol’s 27 September account of a Financial Times story that cites Google’s researchers. Keep them apart.
Which file is the one to look for?
secrets.json in Cline, and config.yaml in Continue, because Google says ACRSTEALER was aimed at both in May 2026. Then look for any other plaintext key, because those two names are examples, not the whole list.
Does MFA stop a stolen session?
Not after the cookie exists. MFA runs when the session is created. Replaying the cookie is a later step.
Is this the same story as the government websites?
No. That is an agent doing more than it was asked, during training and evaluation. This is theft of the credential the agent, or you, would have used. Rotating keys does not fix a sandbox. Pausing training does not fix a key in a config file.
If you do one thing tonight
Search the laptop and the repo for secrets.json. If a live key is in it, that key is a credit card someone has already been told to look for.




