TL;DR: Exposed AI endpoints now behave like non-human identities with direct cost, data, and lateral-movement exposure, not just application risk, as Pillar Security says its honeypots captured 35,000 attack sessions over two months while attackers scanned exposed AI infrastructure, validated endpoints, and resold access through a criminal marketplace, and MCP servers created pivot paths into internal systems.
At a glance
What this is: This research shows how exposed LLM and MCP endpoints are being discovered, validated, and monetised as a commercial attack supply chain.
Why it matters: IAM, NHI, and platform teams need to treat AI endpoints as governed identities because weak exposure controls now create cost, data, and internal pivot risk.
By the numbers:
- The attack activity averaged 972 attacks per day.
- By late January, 60% of total attack traffic came from MCP-focused reconnaissance operations.
- silver.inc resold access at 40-60% discounts while victims paid full retail for unauthorized usage.
Context
LLMjacking is the abuse of exposed or weakly authenticated AI infrastructure to consume model capacity, extract data, and resell access. In practice, the identity problem is not just the model endpoint itself but the wider set of AI services, including Model Context Protocol (MCP) servers, that connect the model to files, databases, and internal APIs.
Pillar Security's investigation frames the issue as a commercial supply chain: scanners find exposed endpoints, validators test them, and marketplaces resell the access. That matters to IAM and NHI teams because the same exposure patterns that create ordinary API risk now also create machine identity abuse, internal pivot paths, and controllable spend leakage.
The article's core warning is that public AI endpoints behave like governed access surfaces, not passive applications. Once they are reachable, they can be enumerated, validated, and traded in ways that look much closer to credential abuse than to simple web probing.
Key questions
Q: What breaks when AI endpoints are exposed without authentication?
A: Unauthenticated AI endpoints become discoverable services that attackers can validate, abuse for inference, and resell as access. The failure is not only unauthorized usage. It is the conversion of a machine service into a tradable identity surface with cost, data, and internal access implications.
Q: Why do MCP servers create more risk than traditional APIs?
A: MCP servers create more risk because they centralize access, make tools discoverable at runtime, and often sit close to the secrets that authenticate downstream calls. Traditional APIs usually expose fixed interfaces; MCP adds a broker that can widen the blast radius if credentials or permissions are too broad. The danger is delegation without enough identity governance.
Q: How do security teams tell whether AI endpoint abuse is becoming a commercial threat?
A: Look for repeated scans, validation traffic, placeholder credential testing, and evidence that the same access patterns are being reused across many targets. When attackers monetize access, the signal is sustained enumeration plus fast follow-on exploitation, not a single noisy probe.
Q: Should organisations treat AI as an application or as an identity?
A: Treat it as an identity when the AI can access data, invoke tools, or participate in workflows that affect business systems. That framing makes least privilege, just-in-time access, and lifecycle governance relevant. If you keep treating it only as an application, you will miss the access and delegation behaviours that actually create risk.
Technical breakdown
How exposed LLM endpoints become monetisable access
Exposed LLM services such as Ollama or vLLM often accept inference requests without a strong authentication boundary, which makes them behave like permissive machine identities. Attackers do not need to compromise the model itself if they can discover a reachable endpoint, probe it for accepted inputs, and reuse it for paid inference or data extraction. The article shows a pipeline of scanning, validation, and resale that turns simple exposure into recurring criminal revenue. In identity terms, the endpoint is being treated as an asset with transferable access value, not as a one-off application weakness.
Practical implication: treat every public AI inference surface as an identity-bearing service and require authentication before exposure becomes tradable access.
Why MCP creates lateral movement through tool access
MCP is a tool-connection layer, not just another API wrapper. When an exposed MCP server can reach file systems, databases, shell commands, or cloud APIs, it turns the AI endpoint into a broker for downstream privileges. That is why the article treats MCP reconnaissance separately: the attacker objective is not only model consumption but infrastructure reach. Once the MCP server is reachable, the access path can cross from AI usage into internal data retrieval and command execution. The risk is delegation without isolation, where the model becomes a front door to privileges it should never hold directly.
Practical implication: place MCP servers behind strong access control and verify that tool permissions are narrower than the model's external reach.
What the commercial marketplace changes about threat modeling
The commercial resale layer changes the economics of exposure. When attackers can validate endpoints quickly and sell access through a marketplace, defenders are no longer dealing with opportunistic curiosity but with a repeatable supply chain. That increases the value of small misconfigurations such as open development instances, public staging environments, and placeholder API keys. For security teams, the important shift is that abuse becomes self-service and scalable. In other words, the endpoint is no longer just vulnerable, it is marketable.
Practical implication: assume exposed AI services will be catalogued, validated, and resold, then remove public reachability before monitoring alone can help.
Threat narrative
Attacker objective: The objective is to turn exposed AI infrastructure into monetisable access that can be resold, abused for compute theft, and used as a pivot into internal systems.
- Entry begins with distributed scanners using internet-wide reconnaissance to identify exposed LLM and MCP endpoints, including unauthenticated services and public development systems.
- Credential access and abuse occur when validators test placeholder API keys, enumerate model capabilities, and confirm that the endpoint accepts unauthorized requests.
- Escalation follows when exposed MCP servers provide reach into files, databases, shell access, and cloud APIs, turning model access into broader infrastructure access.
- Impact is commercial monetisation, data exposure, and lateral movement into internal systems through compromised or openly reachable AI infrastructure.
Breaches seen in the wild
- LiteLLM MCP auth bypass 2026: An exploited LiteLLM MCP auth bypass and default sk-1234 master keys let attackers steal AI gateway master and provider API keys.
- reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
LLMjacking is a machine identity abuse problem before it is an application security problem. Exposed AI endpoints behave like non-human identities because they can accept requests, hold privilege, and create cost without a human operator in the loop. That shifts the governance question from endpoint hardening alone to who can reach, invoke, and resell the service. Practitioners should read this as a lifecycle and access-control issue, not a niche AI anomaly.
MCP access changes the blast radius of exposed AI services. When an AI endpoint is connected to file systems, databases, and internal APIs, the service stops being a model interface and becomes a delegated access path. That means access scope, not just authentication, becomes the decisive control boundary. The practical implication is that AI integration surfaces need governance equivalent to other privileged service accounts.
Commercialisation makes weak AI exposure durable. Once attackers can monetise access through resale, exposed endpoints attract repeat validation and follow-on abuse rather than one-off opportunism. That creates a standing-risk pattern that looks more like credential trafficking than random scanning. Security teams should treat public AI endpoints as part of the organisation's identity perimeter.
Ephemeral AI usage assumptions fail when access is discoverable and reusable. The assumption that AI services are short-lived, low-value, or harmless to expose was designed for contained pilots and internal tooling. That assumption fails when a scanner can find the service, a validator can test it, and a marketplace can resell it. The implication is that access governance must be designed for externally discoverable machine identities, not just internal experimentation.
Operation Bizarre Bazaar shows that AI infrastructure is now inside the adversary's supply chain. The attack pattern combines reconnaissance, validation, and resale into one commercial loop, which means defenders must think in terms of discovery friction, access friction, and downstream privilege boundaries. For NHI governance, the lesson is that AI endpoints need inventory, ownership, and offboarding discipline just like any other machine identity.
From our research library:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
- Read next: Shadow AI and AI Agent Discovery Guide
What this signals
Identity perimeter for AI services: once an LLM endpoint or MCP server is internet-reachable, it should be governed like a discoverable machine identity with explicit ownership, authentication, and offboarding. Discovery and exposure control matter more than post-incident cleanup because marketplaces can monetise access quickly.
Attackers now validate exposed AI services within hours, which means external reachability is the first governance failure to remove. Security teams should assume that scan results, not only logs, will determine how quickly an endpoint is abused, so inventory and exposure review have to sit ahead of detective controls.
For practitioners
- Enforce authentication on every public AI endpoint Require valid credentials for all LLM inference services, staging systems, and customer-facing AI tools before they are reachable from the internet.
- Audit MCP exposure and tool reach Confirm that MCP servers are not directly internet-facing and that their tool connections to files, databases, shell access, and cloud APIs are explicitly restricted.
- Detect placeholder and test-key abuse Alert on authentication attempts that use sk-test, test-token, or dev-key patterns, because those strings indicate automated validation of weakly protected endpoints.
- Inventory production and development AI endpoints Enumerate every exposed AI service, verify ownership, and remove public access from any endpoint that is not required for external use.
- Apply behavioural rate and enumeration controls Use rate limiting and anomaly detection to slow multi-provider probing, burst exploitation, and repeated model capability enumeration from the same source.
Key takeaways
- Exposed AI endpoints can be monetised, resold, and used as pivot points, which moves them into the identity governance domain.
- The article shows a sustained campaign with 35,000 attack sessions and 60% of traffic focused on MCP reconnaissance, not isolated probing.
- Authentication, exposure control, and tool-scope restriction are the controls that most directly reduce this class of abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK define the specific risk controls and attack patterns relevant to this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | AI endpoints and MCP tool bridges enable tool misuse when access is exposed or overbroad. |
| Recommendation — Restrict tool execution paths so exposed AI services cannot misuse downstream tools. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article's core issue is unauthenticated or weakly authenticated access to AI endpoints. |
| NHI-05 — Overprivileged NHI | MCP servers and AI services often hold more authority than the task requires. | |
| NHI-06 — Insecure Cloud Deployment Configurations | Public staging and production exposure is a deployment misconfiguration central to this campaign. | |
| Recommendation — Require strong authentication before any AI endpoint can accept external requests. Trim AI service privilege to the minimum tool and data scope needed for operation. Remove public exposure from AI services that are not intended to be internet-facing. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | Validation, reuse, and MCP pivoting map directly to credential access and lateral movement. |
| Recommendation — Track exposed AI abuse as credential access and lateral movement in detection engineering. | ||
Key terms
- LLMjacking: Abuse of cloud AI services through stolen machine credentials rather than human user accounts. The attacker uses valid non-human identities such as API keys or tokens to enumerate model access, invoke endpoints, and create cost, data, or policy exposure under the victim's tenancy.
- Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Commercial Attack Supply Chain: A commercial attack supply chain is the sequence of roles that turns discovery, validation, and resale into a repeatable criminal business model. In this article, scanners, validators, and marketplaces work together so exposed AI access can be monetised at scale.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org