Skip to content

Topic

API key security

Protection, rotation and spending controls for the credentials that authorise paid access to software and AI services.

Current clusters

security3 publishers

Qrator finds x47.c's AI credit drain works only with a key the attacker already holds

Qrator says x47.c, a Windows botnet sold for up to $950, burns a victim's OpenAI or xAI credit with a valid API key while the website stays up. Website filtering never sees the requests, so the defenses are key revocation and spending caps.

Perspective Coverage

3 publishers
Builder
Builder 35%
Operator
Operator 55%
Investor
Investor 10%

Reality

Evidence40
Adoption
Insufficient
Hype gap+25
Incentives60
Confidence55