Skip to main content

Anthropic's threat report: your AI API key is the loot

Anthropic's September 2026 misuse report shows stolen AI API keys are now a criminal product. Whoever takes yours gets loot, free compute and cover.

Anthropic's threat report: your AI API key is the loot

Ricardo Argüello

Ricardo Argüello
Ricardo Argüello

CEO & Founder

Software Development 4 min read

Somebody was selling cheap Claude access. Anthropic’s write-up of the group says it “turned out to be neither cheap nor actually Claude.”

Customers thought they were getting a discount. Their traffic was quietly routed to a different model, and the reseller’s tooling installed a credential harvester that stole their Anthropic accounts and sold them on to other resellers. Anthropic tracks the group as GTG-50021.

That case sits in the misuse report Anthropic published on September 10, which covers activity it disrupted between December 2025 and August 2026. It also covers weapons development, surveillance, and state propaganda. If you run a business on AI, the section worth your time is the one about keys.

Why a key is worth stealing

Anthropic’s framing is three words. Loot, since stolen keys and accounts resell in established markets. Compute, because the attacker’s workloads now run on someone else’s bill. And cover, which is the one I can’t stop thinking about, because whatever the attacker does gets attributed to whoever owns the key.

When your key is used in an attack, the logs say you did it.

The examples are not theoretical. One hacktivist campaign ran for a month entirely on stolen API keys. ShinyHunters affiliates who found AI keys during an intrusion moved their own attack workloads onto them. And GTG-50020, a Russian-speaking crew that used to go after hotel booking platforms, injected instructions into an AI vendor’s automated evaluation sandbox, walked out with production keys from several model providers, and then hit about thirty AI companies in four days using those keys instead of its own.

Its stated goal was a pre-release Claude model. It never got one. Every key involved came from customers’ environments, not from Anthropic.

Where companies leave them

The report is blunt about the most common source. Legitimate customers who exposed keys by accident, in GitHub repos, mobile app install files, Docker containers, websites, and chatbots.

None of that takes a nation-state. A key in a chatbot’s frontend is a “view source” away. A mobile app can be unpacked. A public container image can be pulled and grepped, and attackers do it automatically.

Then there’s the agent problem. Several actors went after LiteLLM deployments inside AI wrapper services and used prompt injection to get the production API keys out of the containers they ran in. An agent that can read an environment variable is an agent someone will try to talk into printing it. We looked at what it takes to actually watch agents in Uber’s approval-fatigue numbers.

Another actor built sites posing as multi-model intermediaries and pushed installers that impersonated popular AI coding tools, Claude Code among them. They were credential stealers. Reseller and proxy infrastructure shows up all over the report, including behind a China-based studio that ran more than 4,700 AI personas across 20-plus dating apps and talked to at least 25,000 people in two weeks. I use Claude Code every day, and I’d only ever install it from Anthropic.

Anthropic’s own advice, and mine

The report’s recommendation deserves quoting in full: “Organizations should treat AI keys and agent integrations with the same level of seriousness as they do production credentials, because attackers treat them with the same level of seriousness, too.” It adds that AI access should be bought only through authorized channels.

Here’s what that looks like in practice, this week, without starting a project.

  • Count them. Every AI API key in the company, who owns it, which app uses it, where it’s stored. If nobody can produce the list in a day, that’s your first finding.
  • One key per app, with a spend limit. When one leaks, you rotate one.
  • Nothing client-side. No keys in frontends, mobile builds, or container images. A secret scanner on the repo catches a lot of these before they’re committed.
  • Read the bill. Usage is attributed to you, so an unexplained spike in provider spend is often the first sign.

We saw the same shape with Lovable apps leaking data earlier this year. What leaked was everything that had been published around the model.

At IQ Source we audit code and infrastructure for companies that already run AI in production, and AI keys are one of the first things we go looking for. If you can’t say today how many your company has, let’s go find them.

Audit where your AI keys live

Frequently Asked Questions

Anthropic AI security API keys Claude cybersecurity AI agents AI governance

Related Articles

Anthropic Reviewed 141,006 Runs and Found 3 Real Hacks
Business Strategy
· 8 min read

Anthropic Reviewed 141,006 Runs and Found 3 Real Hacks

Anthropic disclosed three cases where Claude broke into real companies during evaluations. It found them by reading old transcripts, not by monitoring.

Anthropic Claude AI security
OpenAI's Agent Escaped Its Sandbox and Hacked Hugging Face
Business Strategy
· 6 min read

OpenAI's Agent Escaped Its Sandbox and Hacked Hugging Face

OpenAI admits a test model broke out of a 'highly isolated' environment and hacked Hugging Face to steal the answer key to its own cybersecurity exam.

OpenAI Hugging Face AI containment
Anthropic Leaked Mythos: Your Trust Model Just Changed
Business Strategy
· 6 min read

Anthropic Leaked Mythos: Your Trust Model Just Changed

Anthropic exposed ~3,000 internal documents through a CMS error, including Claude Mythos, their most advanced model. What changes for your AI strategy.

Anthropic Claude data leak enterprise trust
AI Code Security: What Your Traditional Scanner Misses
Software Development
· 6 min read

AI Code Security: What Your Traditional Scanner Misses

Static scanners catch known patterns but miss context-dependent vulnerabilities. How AI-powered code analysis closes the gap for mid-market companies.

code security vulnerability analysis artificial intelligence
Project Glasswing: AI Found What 27 Years of Humans Missed
Business Strategy
· 8 min read

Project Glasswing: AI Found What 27 Years of Humans Missed

Anthropic launched Claude Mythos Preview with 11 partners to defend critical infrastructure. What changes for your security posture and what to do now.

cybersecurity Anthropic Claude Project Glasswing
AI Agents This Week: Products, Acquisitions, and Risks
AI & Automation
· 7 min read

AI Agents This Week: Products, Acquisitions, and Risks

Perplexity Computer, Anthropic acquires Vercept, the OpenClaw security crisis, and NIST agent standards. What these stories mean for your B2B company.

AI agents Perplexity Computer AI security