• News/
  • https://www.darkreading.com/application-security/llm-hijackers-deepseek-api-keys

LLM Hijackers Quickly Incorporate DeepSeek API Keys

Dark Reading
·
Nate Nelson
·
Published Feb 7, 2025
·
Updated

Sophisticated "LLMjacking" operations have obtained stolen access to DeepSeek models, just weeks after their public release. LLMjacking, like proxyjacking and cryptojacking, involves the illicit use of someone else's computing resources for one's own purposes. In this case, it's individuals using popular and otherwise expensive large language models (LLMs) from OpenAI, Anthropic, etc., to generate images, circumvent national bans, and more, while passing the bill along to someone else. Most recently, researchers from Sysdig observed hyperactive LLMjacking operations integrating access to models developed by DeepSeek. After the company released its DeepSeek-V3 model on Dec. 26, it only took LLMjackers a few days to obtain stolen access. Similarly, DeepSeek-R1 was released on Jan. 20, and attackers had it in their hands the very next day. "This isn't just a fad anymore," Sysdig cybersecurity strategist Crystal Morin says of LLMjacking. "This is far beyond where it was when we first discovered it last May." At scale, LLM usage can grow rather expensive. For instance, according to Sysdig's back-of-the-envelope calculations, 24/7 usage of GPT-4 could cost an account holder north of half a million dollars (though DeepSeek, at present, is orders of magnitude less expensive). In order to enjoy these models without having to incur their costs, attackers steal credentials for cloud services accounts, or application programming interface (API) keys associated with specific LLM apps. The...

Read full article

Affected Software

4 affected components
DeepSeek DeepSeek-V3
DeepSeek DeepSeek-R1
DeepSeek DeepSeek-V3
DeepSeek DeepSeek-R1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the focus of the article regarding LLM hijacking?

The article focuses on the rapid exploitation of DeepSeek API keys by LLM hijackers shortly after their release.

2

What type of cybercrime does LLM hijacking resemble?

LLM hijacking, or 'LLMjacking', is similar to proxyjacking and cryptojacking, where unauthorized use of resources occurs.

3

Which specific DeepSeek products are mentioned as affected?

The affected DeepSeek products mentioned are DeepSeek-V3 and DeepSeek-R1.

4

What are the potential consequences of these security breaches?

The potential consequences include unauthorized access to computational resources and misuse of AI capabilities.

5

Why is the timing of the exploit significant in the article?

The timing is significant because it illustrates how quickly cybercriminals adapt to new technologies after their public release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203