September 21, 2026
One stolen token opened up the entire cloud in 3 hours: an AI agent ran the attack
AI keys have become loot in their own right: someone else’s requests run at the victim’s expense and under their name.

One developer token was stolen. Three hours later, the company’s cloud had a new administrator.
That is how Anthropic described the work of a ShinyHunters affiliate in its September 10, 2026 report, “Detecting and countering misuse of AI”: 154 pages on Claude abuse from December 2025 through August 2026. Reconnaissance and initial access took such attacks 2–3 hours, while defenders needed days to respond.
Anthropic calls this operating model vibe hacking. The operator sets a broad goal such as “take stolen access and extract data”; the model then examines the environment, writes and runs scripts, delivers a summary, and repeats the cycle until the task is complete.
The key became loot. Stolen AI keys are now valuable in themselves. They are resold, used to run someone else’s workloads at the owner’s expense, and logged by the vendor as activity under a legitimate account. The keys came from customer environments; Anthropic’s own systems were untouched.
They are hunted at scale. A French-speaking participant known online as frkoo built an assembly line on 10 AWS EC2 machines: he downloaded 1,8 million Android apps from several stores, unpacked them, and ran TruffleHog to search for keys embedded inside. The findings went into a Telegram group organized into more than 100 source types.
Then the count reaches dozens of companies at once. One session-storage dump yielded more than 2100 sets of Azure AD tokens from over 40 corporate accounts in about 34 hours. A breach at one SaaS provider exposed data from around 200 of its client organizations; 1 TB was taken from a technology provider.
What to do with keys. Anthropic advises treating AI keys and agent integrations as production access, “because attackers treat them exactly that way.” Analyses of the report reduce this to three things. Inventory every key and session token, including those embedded in mobile builds, containers, and public repositories. Do not keep production keys in client applications and test sandboxes; issue them server-side with limited permissions and enable automatic rotation. Monitor outbound traffic to models, because a spike in calls now reads as a sign of compromise.
Next, defense comes down to speed: controls designed for a human at a keyboard against an attack moving at machine speed.
