XT.PT AI supply chain → This story
Analysis AI supply chain

Loot, compute, cover: what a stolen Claude API key buys

Anthropic's September 10 threat report treats AI API keys, eval sandboxes, LiteLLM wrappers and discount resellers as attack surface, and says who was working it.

Claude Logo silicon

Anthropic published "Detecting and countering misuse of AI: September 2026" on September 10. It covers activity the company says it disrupted between December 2025 and August 2026, across seven harm areas from cyber operations to illicit distillation. A large part of it concerns illicit distillation. The section with the most direct consequences for anyone who holds an AI API key is shorter, and is titled "AI supply chain as target, loot, and attack compute."

One framing note first. This is Anthropic's account of its own investigations, including its attributions; the report is the only evidence here. It also says that Claude Haiku, Sonnet and Opus models were used, and that "None of the misuse cases involved the use of Claude Fable or Mythos-class models, with the exception of one illicit distillation case."

Three things a key buys

The report's argument is that an AI credential is worth more to an attacker than its resale price. In its words, operators who obtain one gain three things at once:

Loot: Stolen keys and accounts have resale value in established markets; Compute: Having the credentials means that their attack workloads can run at someone else's expense; Cover: The activity is attributed to the credential's legitimate owner.

Anthropic Threat Intelligence, September 2026 report

The case studies put numbers on the compute and cover parts. Suspected ShinyHunters affiliates (Anthropic's GTG-50014) stole a target's AI API keys during intrusions, and one of those keys "was then used by the attacker for roughly three weeks to conduct secondary attacks." A single French-speaking hacktivist (GTG-50029) "ran for a month entirely on stolen API keys," using a custom Rust scanner that validated exposed keys in public containers and then rotated them "across a local proxy layer" so the traffic blended in with the legitimate owner's. Anthropic adds that "In every instance, the API keys involved were stolen from Anthropic customers' environments," and that its own systems were not compromised.

The cover point is the one defenders should sit with. When a stolen key runs an intrusion, the abuse signal attaches to the victim's account, not the attacker's.

Where the keys come from

The most common source, per the report, is the legitimate customer: keys "inadvertently exposed" in "public code such as GitHub, mobile application install files, Docker containers, websites, and chatbots." The scale in one case is industrial. A ShinyHunters-linked operator ran a pipeline on 10 AWS EC2 workers that "mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog," routing verified finds to a Telegram group "organized into over 100 source types."

The second source is the discount. Anthropic describes sites posing as intermediaries that offered cheap access to frontier models and pushed client applications "often spoofing as popular AI harnesses including Claude Code" that were in fact credential harvesters, and that kept harvesting new sessions after victims reset compromised keys. One group, GTG-50021, sold "cheap Claude access" that "turned out to be neither cheap nor actually Claude": customer traffic was silently proxied to a different model while the tooling stole their Anthropic credentials. The report publishes that group's domains as indicators of compromise, and a full IOC file accompanies the report.

The sandbox that handed over its keys

The case that earns the section its title is GTG-50020, described as a Russian-speaking, financially motivated actor with a history of intrusions against hotel booking and fintech platforms. Its move into AI went through a vendor's test harness: "By injecting malicious instructions into an AI vendor's automated evaluation sandbox, the actor caused the sandbox to hand over the credentials it held," including production API keys from multiple providers. The actor then switched its own intrusion workloads onto the victim's keys. A follow-on campaign from the same infrastructure "attacked roughly thirty AI companies in about four days," reusing one working attack path against all of them. The stated goal, pursued across "more than a dozen avenues," was a pre-release Claude model. Anthropic says every path failed.

The same pattern appears one layer down. The report says multiple actors compromised "AI wrapper services' implementation of LiteLLM" and "used prompt injection to exfiltrate the production API keys used in their cloud-hosted container environments." It does not name the services or say which weakness was used, so this is a class of failure, not an advisory.

The common design flaw is structural. An evaluation sandbox or a model proxy exists to run untrusted input through a model, and both cases describe one that also held the credentials it spends. Anthropic's own summary: "This case is the clearest demonstration to date that the AI supply chain has become a deliberate criminal target."

A control that was replayed

One technical detail from the distillation section belongs here too, because it is a defensive control that failed. Claude returns what the report calls a "thinking signature" instead of the raw thinking: a reference the API uses to look up the trace on later calls. Anthropic says Moonshot saved signatures, started new sessions and elicited Claude "to convert the reasoning signature back into the full reasoning trace," and that DeepSeek used "the same cross-session replay attack." The report says only that Anthropic is "introducing new methods to strengthen our defenses against these tactics"; it gives no technical detail of the fix.

The same section alleges both labs silently relayed some of their own customers' requests to Claude, including, in the examples given, live credentials. The lesson for users is the one GTG-50021's customers learned: the model on the far side of an intermediary is whatever the intermediary says it is.

What the report asks for

Anthropic's recommendation is short. Organizations should "treat AI keys and agent integrations with the same level of seriousness as they do production credentials," and "AI access should be purchased only through authorized channels." It names "sandboxes, proxies, and resellers" as part of the attack surface.

Read against the case studies, that translates into checks most teams can run this week (these are XT.PT's reading, not the report's list): scan your own shipped artifacts, including mobile builds and container images, with the same secret scanners the attackers use; keep production keys out of any environment whose job is to feed untrusted input to a model; and treat unexplained usage on an AI key as a possible intrusion, not a billing anomaly, because in the cases above that usage was somebody else's attack.

Primary sources: Anthropic, Detecting and countering misuse of AI: September 2026, full report PDF, indicators of compromise CSV, read 2026-09-15.

Corrections and source documents: contact the desk
Read next →
Read next
Edge devices · 4 min

NetScaler 14.1-73.37 fixes eight CVEs, and the exploited CVE-2026-88771 needs no special configuration

WordPress · 4 min

WordPress 7.1.2 fixes CVE-2026-87902, a page-template bug exploited within three days