Key Takeaways
- Fraudsters exploited Canva’s AI credit system via “seat cycling” on its Leonardo.ai integration, which Canva acquired for $320 million in 2024, to amass and resell generative AI tokens.
- The exploit targeted Canva Business trial users who gained access to Leonardo.ai’s Essential plan, providing 8,500 fast tokens monthly and a 25,500 token rollover bank per team member, enabling continuous account creation and deletion for credit harvesting.
- Canva responded by limiting Leonardo.ai access to paid Business members only, after a Stripe analysis found roughly 7.4% of AI account sign-ups industry-wide are linked to free account abuse. Every token harvested by a fraudster is compute that Canva pays for, and the people running the scheme never had to pay for a single one. By repeatedly spinning up and deleting Business trial accounts tied to Canva’s Leonardo.ai integration, fraudsters built a repeatable pipeline for harvesting generative AI credits and selling them at a discount on grey markets. Canva has since closed the loophole, but the episode shows how quickly a generous trial tier can become an attack surface.
How the Scheme Worked
The method, dubbed “seat cycling” or the “Canva method,” relied on a specific perk built into the integration. Canva Business trial users were granted access to Leonardo.ai’s Essential plan, which came with 8,500 fast tokens per month and a 25,500 token rollover bank for accessing generative AI features. Each team member on a trial received their own individual allocation.
That per-seat structure was the opening. Fraudsters would spin up new team seats within a trial account, each one instantly receiving its own token allowance. Once stocked, they sold access to those accounts on grey markets. When the credits ran dry, they deleted the accounts and started again. The cycle could repeat indefinitely, with no legitimate payment required at any point.
Canva’s Fix
Canva confirmed it made “some updates to address fraudulent activity,” describing the abuse as accounts “being used to access AI services beyond normal limits.” The company responded by restricting Leonardo.ai access to paid Business members only, removing the trial-tier entry point the scheme depended on.
The financial exposure is harder to quantify precisely, but a Stripe analysis found roughly 7.4% of AI account sign-ups across the industry are linked to free account abuse, which suggests Canva is far from the only platform dealing with this.
Pressure on the Numbers
Investor Blackbird Ventures is reported to have cut its own valuation of Canva to roughly AUD $49 billion, according to reports. Token fraud alone does not explain a valuation adjustment of that scale, and it would be wrong to suggest it does, but it adds cost. At scale, compute consumed by fraudsters is not trivial, particularly for a company that has staked a large part of its product roadmap on AI. Canva Code 2.0 illustrates how central AI has become to the platform’s pitch, which makes protecting the economics of those features more urgent.
A Wider Pattern
The Canva exploit is one version of a problem that keeps turning up across AI platforms. Free tiers and trial periods are designed to win users, but the same generosity that attracts genuine customers also attracts people looking to monetise the access itself. The more capable the underlying model, the more valuable the tokens, and the stronger the incentive to find gaps in access controls.
Canva has faced other platform abuse as well. Its public-sharing feature has reportedly been used to distribute phishing links, with malicious URLs embedded inside shared designs. A different kind of attack, but the same logic: a trusted, widely used platform becomes cover for something harmful. As AI-enabled fraud scales in 2025 the pattern is consistent enough across platforms that it warrants attention at the product design stage, not just the incident response stage.
The seat cycling fix closes one specific gap. Staying ahead of the next one is a different, ongoing problem.
Originally published at https://autonainews.com/canvas-320m-ai-buy-exploited-in-seat-cycling-fraud/
Top comments (0)