AI Denial-of-Service Attack

AI Denial-of-Service Attack

A leaked API key can spend your AI budget in an afternoon.

What Is AI Denial-of-Service Attack?

Every call to a large model buys compute, so an unprotected AI endpoint is a spending account with an API in front of it. Attackers do not need to take the service down, only to keep it busy. You'll find an API key in a public commit and run up the bill with a slow trickle of maximum-cost prompts, then take the defender's seat: read the budget alert, watch cost and latency climb, trace the requests through the console logs, revoke the key, and set a rate limit and a spend threshold.

What You'll Learn in AI Denial-of-Service Attack

AI Denial-of-Service Attack — Training Steps

  1. Setting Up the Scan

    Bob opens his credential scanning dashboard – a tool that monitors public code repositories for exposed API keys, tokens, and cloud secrets. He is about to target CypherPeak Technologies' public GitHub organization.

  2. Running the Scan

    Bob enters CypherPeak's GitHub organization URL into the scanner and starts a credential sweep across all their public repositories.

  3. A Critical Finding

    The scanner analyzed 847 repositories and 12,403 recent commits. Among six total secrets found, one stands out: a production OpenAI API key exposed in a configuration file committed just minutes ago to CypherPeak's AI gateway project.

  4. Examining the Commit

    Bob clicks through to the source commit to examine the exposed credential in its original context. The GitHub commit diff shows the full configuration file with the API key in plain text.

  5. The Exposed API Key

    The commit diff reveals a production API key hardcoded directly in a Python configuration file. This key provides full access to CypherPeak's AI platform API with no rate limiting or budget restrictions attached.

  6. Preparing the Attack

    Bob opens a terminal to test whether the stolen API key is still active. If the key works and has no rate limiting, he can launch a denial-of-wallet attack to drain CypherPeak's entire AI budget.

  7. Testing the Stolen Key

    Bob sends a simple API request using the stolen key to verify it works. A successful response with no rate limit headers will confirm the key is exploitable.

  8. The Key Works

    The API responds successfully. The response confirms the key is valid – and critically, the rate_limit and budget_cap fields are both null . There are no protections on this key whatsoever.

  9. Launching the Attack

    The key works and has no protections. Bob launches an automated attack script that sends recursive expansion prompts, each designed to consume the maximum 32,768 tokens per request. He runs only 3 worker threads: the request rate stays close to CypherPeak's normal traffic, so no request-rate alarm fires, while every request is as expensive as he can make it.

  10. Attack in Progress

    The attack script starts 3 worker threads, each sending recursive expansion prompts at maximum token output. Each request takes about a minute to generate, so the workers send about 3 requests a minute. Within the first minute the cost rate reaches $12.40 per minute, over $700 per hour.

Security Framework Coverage

OWASP LLM Top 10

  • LLM06:2026 Unbounded Consumption
  • LLM10:2025 Unbounded Consumption

CWE

  • CWE-770 Allocation of Resources Without Limits or Throttling

CIS Controls

  • CIS 16 Application Software Security

NIST CSF

  • PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
  • PR.PS Platform Security