<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Thinus Swart</title>
    <description>The latest articles on DEV Community by Thinus Swart (@thinusswart).</description>
    <link>https://dev.to/thinusswart</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4156605%2F4baed207-d471-4234-aa44-eefbfe510cf9.jpg</url>
      <title>DEV Community: Thinus Swart</title>
      <link>https://dev.to/thinusswart</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/thinusswart"/>
    <language>en</language>
    <item>
      <title>Passkey Adoption Is Rising, but Is It Worth It Yet?</title>
      <dc:creator>Thinus Swart</dc:creator>
      <pubDate>Fri, 02 Oct 2026 08:54:16 +0000</pubDate>
      <link>https://dev.to/auth0/passkey-adoption-is-rising-but-is-it-worth-it-yet-46k2</link>
      <guid>https://dev.to/auth0/passkey-adoption-is-rising-but-is-it-worth-it-yet-46k2</guid>
      <description>&lt;p&gt;&lt;a href="https://learnpasskeys.io/introduction" rel="noopener noreferrer"&gt;Passkeys&lt;/a&gt; are fast becoming an appealing alternative to passwords. Built on standards developed by the &lt;a href="https://fidoalliance.org/" rel="noopener noreferrer"&gt;FIDO Alliance&lt;/a&gt; and supported by companies like Apple, Google, and Microsoft, passkeys allow users to authenticate with biometrics, device PINs, or hardware-backed credentials instead of remembering passwords.&lt;/p&gt;

&lt;p&gt;For enterprises, there are some compelling arguments for switching to passkeys: stronger protection against phishing attacks and a promised, improved user experience. However, adopting passkeys also raises some questions around legacy systems, device management, recovery workflows, and rollout strategies.&lt;/p&gt;

&lt;p&gt;This article explains what passkeys are, how synced and device-bound passkeys differ, the operational challenges to consider, and where passkeys offer advantages over traditional passwords. In short, you’ll learn whether passkey adoption is truly worth it yet.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Are Passkeys?
&lt;/h2&gt;

&lt;p&gt;Passkeys are a &lt;a href="https://auth0.com/docs/authenticate/passwordless" rel="noopener noreferrer"&gt;passwordless authentication method&lt;/a&gt; that uses &lt;a href="https://auth0.com/docs/secure/multi-factor-authentication/fido-authentication-with-webauthn" rel="noopener noreferrer"&gt;public-key cryptography&lt;/a&gt; to verify a user’s identity. Instead of creating and storing a traditional password, a user’s device generates a cryptographic key pair: a private key that stays securely on the device and a public key that is shared with the application or service.&lt;/p&gt;

&lt;p&gt;When the user signs in to an application or a website, a challenge, that is, a random cryptographic string, is sent to their device. The user unlocks access to the private key stored on their device using a biometric factor like a fingerprint or face scan, or a device PIN. The private key then signs the challenge, which is sent back to the application or website for verification. The following diagram shows this sign-in flow from challenge to verified access.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fuqewub7182etv4cqqmzq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fuqewub7182etv4cqqmzq.png" alt="Diagram depicting sign-in flow from challenge to verified access" width="800" height="996"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Because the private key never leaves the device and there is no shared secret to steal, passkeys are far more resistant to phishing, credential theft, and password reuse attacks than traditional passwords.&lt;/p&gt;

&lt;p&gt;Passkeys are built on standards developed by the FIDO Alliance and the &lt;a href="https://www.w3.org/" rel="noopener noreferrer"&gt;World Wide Web Consortium (W3C)&lt;/a&gt;, allowing them to work across modern browsers, operating systems, and devices. Major platforms such as Apple, Google, and Microsoft have integrated passkey support directly into their ecosystems, helping to accelerate adoption across both consumer and enterprise environments.&lt;/p&gt;

&lt;h2&gt;
  
  
  Different Types of Passkeys
&lt;/h2&gt;

&lt;p&gt;Broadly speaking, you will encounter two main types: synced passkeys and device-bound passkeys.&lt;/p&gt;

&lt;h3&gt;
  
  
  Synced passkeys
&lt;/h3&gt;

&lt;p&gt;Synced passkeys are designed for convenience and portability. These passkeys are securely synchronized across a user’s devices through a cloud ecosystem such as Apple iCloud Keychain or Google Password Manager. This allows users to enroll a passkey on one device and use it on another device connected to the same account.&lt;/p&gt;

&lt;p&gt;Synced passkeys can significantly improve the user experience and reduce onboarding friction. Employees can move between laptops, phones, and tablets without repeatedly registering new credentials. However, organizations might have concerns about control and recovery, particularly in regulated environments where credentials being synchronized through personal cloud accounts could introduce governance or compliance challenges.&lt;/p&gt;

&lt;h3&gt;
  
  
  Device-bound passkeys
&lt;/h3&gt;

&lt;p&gt;Device-bound passkeys remain tied to a specific device or hardware authenticator and are not synchronized elsewhere. Examples include credentials stored in hardware security keys, such as &lt;a href="https://www.yubico.com/" rel="noopener noreferrer"&gt;Yubico&lt;/a&gt;, or TPM-backed credentials managed directly on enterprise-controlled devices.&lt;/p&gt;

&lt;p&gt;They provide stronger control over where credentials are stored and are often preferred in high-security environments. If an attacker compromises a cloud account, they do not also gain access to the credentials because the passkey never leaves the original device. The tradeoff, however, is a loss of usability and convenience. Replacing lost devices, onboarding additional devices, or recovering credentials can become more operationally complex for both users and IT teams.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Are the Main Benefits of Using Passkeys in the Enterprise?
&lt;/h2&gt;

&lt;p&gt;The biggest benefit for considering passkeys is risk reduction.&lt;/p&gt;

&lt;p&gt;Because authentication is tied to a set of cryptographic credentials, rather than a shared secret, you can dramatically reduce your users' exposure to phishing campaigns and other credential-related attacks. For phishing in particular, since the private key is bound to a specific web domain, it cannot be used to authenticate the user on a different domain.&lt;/p&gt;

&lt;p&gt;Passkeys can also improve your efficiency. Password resets are probably one of the more common helpdesk requests in many companies. Reducing the reliance on passwords can lower your support overhead. Your users will also appreciate the smoother sign-in experience.&lt;/p&gt;

&lt;p&gt;Finally, the switch to passkeys definitely aligns more closely with &lt;a href="https://auth0.com/blog/enterprise-trust-race" rel="noopener noreferrer"&gt;modern security strategies&lt;/a&gt;. Companies are actively pursuing zero-trust architectures and stronger MFA adoption. Passwordless initiatives like passkeys fit neatly into those efforts, and can help enterprises modernize their authentication strategy.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Are Some of the Main Challenges of Using Passkeys?
&lt;/h2&gt;

&lt;p&gt;In spite of the benefits, switching to passkeys is not as simple as just enabling a new login option.&lt;/p&gt;

&lt;p&gt;Many organizations have older applications and internal systems that do not support passkeys and might need to be retrofitted to do so. Third-party platforms also might not support passkeys yet, so you are stuck with using passwords on those platforms until they decide to support them.&lt;/p&gt;

&lt;p&gt;In reality, this means that enterprises would probably need to manage a &lt;a href="https://auth0.com/blog/secure-hybrid-authentication-architecture-with-auth0/" rel="noopener noreferrer"&gt;hybrid authentication model&lt;/a&gt; during any transition period.&lt;/p&gt;

&lt;p&gt;Recovery and lifecycle management also plays a much bigger role with passkeys. When employees lose a device or leave the company, IT teams need clear processes for credential recovery, re-enrollment, and revocation. These workflows can be more complex than traditional password reset processes.&lt;/p&gt;

&lt;p&gt;Because passkeys are more than likely device-bound, there is no central credential to reset. Instead, IT teams must verify the user's identity through a separate, out-of-band process before issuing a new enrollment, and any previously registered passkeys on lost or decommissioned devices need to be explicitly revoked.&lt;/p&gt;

&lt;p&gt;Finally, organizations need to decide whether they prefer device-bound or synced passkeys, and whether different choices should apply to contractors and remote employees.&lt;/p&gt;

&lt;h2&gt;
  
  
  What About Legacy Systems?
&lt;/h2&gt;

&lt;p&gt;If you are considering implementing passkeys for your organization, legacy systems are probably going to be one of the bigger hurdles. Older applications might not support modern authentication standards like &lt;a href="https://www.webauthn.me/introduction" rel="noopener noreferrer"&gt;WebAuthn&lt;/a&gt; or &lt;a href="https://fidoalliance.org/specifications/" rel="noopener noreferrer"&gt;FIDO2&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;That does not always mean that passkeys are off the table. You can implement identity platforms or &lt;a href="https://auth0.com/docs/authenticate/single-sign-on" rel="noopener noreferrer"&gt;single sign-on (SSO)&lt;/a&gt; platforms in front of legacy applications to handle the authentication in a more modern way.&lt;/p&gt;

&lt;p&gt;In practice, most organizations will likely operate hybrid authentication environments for some time, using passkeys where they fit naturally while maintaining alternative authentication methods for systems that cannot support them yet.&lt;/p&gt;

&lt;h2&gt;
  
  
  Consider a Phased Rollout
&lt;/h2&gt;

&lt;p&gt;For most organizations, a phased rollout is usually the most practical approach to any new implementation, but especially for passkeys. Rather than forcing the entire company to migrate immediately, it is a good idea to start with smaller user groups or lower-risk applications.&lt;/p&gt;

&lt;p&gt;A gradual rollout allows IT and security teams to evaluate the user experience at multiple points during the process. This can help to identify compatibility issues, and to refine existing recovery and support processes before you expand to a larger audience.&lt;/p&gt;

&lt;p&gt;Passkeys are likely to coexist with passwords for some time, especially if legacy systems are involved. A phased rollout will help organizations to modernize any internal applications and systems they might have under their control.&lt;/p&gt;

&lt;h2&gt;
  
  
  Passkeys vs. Passwords
&lt;/h2&gt;

&lt;p&gt;Passwords remain an embedded part of enterprise environments everywhere. Despite their weaknesses, they offer flexibility and a universal compatibility that systems and users understand. Given that you will likely still have to rely on passwords for some time, you might be weighing up whether passkeys deserve a place in your authentication strategy.&lt;/p&gt;

&lt;p&gt;This is not simply a case of "new versus old". Passkeys were created to solve many of the security and usability problems that passwords have struggled with traditionally, as can be seen in the pros and cons of both authentication methods.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Pros&lt;/th&gt;
&lt;th&gt;Cons&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Passwords&lt;/td&gt;
&lt;td&gt;Universally supported by practically any system Familiar to users and systems alike Easier to centrally control and reset Does not require modern devices or hardware Simpler to use in legacy environments&lt;/td&gt;
&lt;td&gt;Vulnerable to phishing attacks Users often create weak or reused passwords &lt;a href="https://auth0.com/docs/secure/multi-factor-authentication" rel="noopener noreferrer"&gt;MFA&lt;/a&gt; adds friction and can still be &lt;a href="https://securityboulevard.com/2026/05/consentfix-v3-automates-oauth-abuse-to-bypass-mfa-and-hijack-azure-accounts/" rel="noopener noreferrer"&gt;bypassed&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Passkeys&lt;/td&gt;
&lt;td&gt;Strong resistance to credential theft and phishing Faster and smoother login experience Reduces password resets and support overhead No passwords for users to remember&lt;/td&gt;
&lt;td&gt;Legacy systems may not support them Losing a device can cause significant headaches Enterprise rollouts require planning and user education Synced passkeys could raise governance concerns&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  So, Is Passkey Adoption Worth It?
&lt;/h2&gt;

&lt;p&gt;In many cases, the answer is "yes", but with an important caveat: the value you might derive from switching to passkeys depends heavily on your company's infrastructure and security priorities.&lt;/p&gt;

&lt;p&gt;For enterprises that are already investing in modern identity platforms, zero-trust initiatives and managed devices, passkeys are a natural fit and can provide meaningful security and usability improvements for large parts of your organization.&lt;/p&gt;

&lt;p&gt;The strongest argument for passkeys is that they directly address many of the weaknesses that have plagued passwords for years. Passkeys reduce exposure to phishing and credential theft. Passkeys in general also make the authentication process feel smoother for most users. No need to remember long passwords, or open your password manager for the umpteenth time.&lt;/p&gt;

&lt;p&gt;With all that said, that does not mean passkeys are a magic replacement for all your authentication woes. Enterprises still need to think carefully about recovery workflows, device management and legacy application support. You will need to have governance policies and employee training guides in place before you transition to passkeys.&lt;/p&gt;

&lt;p&gt;Passkeys are not an "all or nothing" decision to make, but something that requires a gradual and strategic adoption plan. They are probably worth considering if your organization answers "yes" to at least two of these statements:&lt;/p&gt;

&lt;p&gt;You want stronger protection against phishing and credential-related attacks.&lt;br&gt;
You manage corporate devices for your employees.&lt;br&gt;
You are already in the process of modernizing your &lt;a href="https://auth0.com/docs/get-started/identity-fundamentals/identity-and-access-management" rel="noopener noreferrer"&gt;IAM infrastructure&lt;/a&gt;.&lt;br&gt;
You want to reduce password-related support costs and friction.&lt;br&gt;
So passkeys might not completely replace passwords overnight, but for many enterprises, they are a mature enough technology to justify consideration as part of a long-term authentication plan.&lt;/p&gt;

&lt;h2&gt;
  
  
  Passkeys Are a Strategic Decision
&lt;/h2&gt;

&lt;p&gt;The question of whether to adopt passkeys is less about whether they are inherently good or bad, and more about whether your organization is ready to support them effectively. Factors like device management, governance policies, and infrastructure readiness play an important role in figuring out whether passkeys will provide value in your environment.&lt;/p&gt;

&lt;p&gt;For many companies, the path forward should be a gradual one: Introduce passkeys where they make the most sense, while continuing to support traditional authentication methods where necessary. Adoption should continue to grow across third-party platforms and other enterprise tooling too, and you can enable passkeys on these platforms as they become available.&lt;/p&gt;

&lt;p&gt;Passkeys are less of an experimental feature like they were a few years ago, and more of a serious consideration for a long-term authentication strategy.&lt;/p&gt;

</description>
      <category>identity</category>
      <category>passkeys</category>
    </item>
    <item>
      <title>LLMjacking and the Hidden Cost of a Stolen API Key</title>
      <dc:creator>Thinus Swart</dc:creator>
      <pubDate>Fri, 02 Oct 2026 08:31:17 +0000</pubDate>
      <link>https://dev.to/auth0/llmjacking-and-the-hidden-cost-of-a-stolen-api-key-2all</link>
      <guid>https://dev.to/auth0/llmjacking-and-the-hidden-cost-of-a-stolen-api-key-2all</guid>
      <description>&lt;p&gt;For the past few years, one topic has constantly been on the minds of tech professionals around the world: AI.&lt;/p&gt;

&lt;p&gt;AI is no longer just another piece of the tech stack but is fast becoming its foundation. Major business features, like customer support and data analysis pipelines, are being shifted to Large Language Models (&lt;a href="https://en.wikipedia.org/wiki/Large_language_model" rel="noopener noreferrer"&gt;LLMs&lt;/a&gt;), and businesses are more dependent on LLMs every day. That dependency has not gone unnoticed by attackers. As LLMs become more central to core business processes, they have become a valuable target in their own right.&lt;/p&gt;

&lt;p&gt;This article explains how LLMjacking works, the potential risks and costs associated with an attack, and what you can do to detect and prevent it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is LLMjacking?
&lt;/h2&gt;

&lt;p&gt;LLMjacking involves attackers hijacking access to your LLM. Although the widespread adoption of LLMs is a relatively recent development, LLMjacking itself is just a different spin on a familiar attack: Gaining access to stolen or exposed credentials. Before the LLM era, criminals used to look for AWS or GCP access keys, which could potentially give them access to compute resources, storage, and sensitive company information.&lt;/p&gt;

&lt;p&gt;The repercussions from stolen and exposed credentials are bad enough, but LLMjacking has the potential to cause significantly more harm (financial or reputational) to both an organization and its clients. LLM usage is often metered and expensive, so abuse can translate directly into financial impact. If the key is tied to custom models, internal prompts, or sensitive data pipelines, the risk is no longer solely about compute resources. Unlike a stolen cloud key, a compromised LLM credential can give an attacker access to far more than raw data.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Harm Does LLMjacking Cause?
&lt;/h2&gt;

&lt;p&gt;The impact of an LLMjacking incident goes beyond unexpected API usage or inflated billing. It can very quickly escalate into a significant financial loss, disruption of day-to-day operations, and exposure of sensitive company or customer data.&lt;/p&gt;

&lt;p&gt;Understanding these risks in detail is important because the potential consequences extend across multiple aspects of your business.&lt;/p&gt;

&lt;h3&gt;
  
  
  Financial impact of LLMjacking
&lt;/h3&gt;

&lt;p&gt;This is usually the first place where you notice that "something is wrong". If you see the impact of LLMjacking in your bills, it is likely that the attack has already done significant damage. An attacker with unfettered access to your LLM API could easily have used it to spin up spam email templates, phishing sites, and even malware for their own nefarious purposes.&lt;/p&gt;

&lt;p&gt;If you have usage and billing limits, you might think you are safe. There is only so much an attacker could do with your LLM, right? However, any downstream agentic processes or automated workflows dependent on the LLM will also be affected. This could have an even bigger financial impact on the organization, especially if those processes are tied to critical business functions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Malicious use of custom models
&lt;/h3&gt;

&lt;p&gt;Some organizations rely heavily on custom models, usually trained on internal documents and business processes to help the model better understand how your organization operates. Increasingly, these kinds of models are being used for new and existing employees as a kind of "wiki". If you are not sure what to do with a specific document or which employee to speak to about a specific situation, just ask the LLM using the custom model.&lt;/p&gt;

&lt;p&gt;Should an attacker gain access to this model, however, they could gain knowledge about your organization that was never intended to be public. This kind of information could be used to further extend their foothold on your network, or it could allow an attacker to sell this information on the dark web.&lt;/p&gt;

&lt;h3&gt;
  
  
  Data poisoning
&lt;/h3&gt;

&lt;p&gt;In some environments, these same custom models are constantly being refined and trained using new organizational or financial data. Should an attacker gain access to the training data or the method used to train your custom models, it can create opportunities for data poisoning.&lt;/p&gt;

&lt;p&gt;An attacker could gradually influence the model over time to provide misleading or biased responses to employees. While this is a more time-consuming exercise, it allows them to nudge decisions, surface false information, or steer internal processes. Any changes made to the model are usually very subtle and therefore difficult to detect.&lt;/p&gt;

&lt;h2&gt;
  
  
  Different Attack Vectors
&lt;/h2&gt;

&lt;p&gt;As discussed before, LLMjacking is not really something new. These attack vectors are similar to the ones already employed by attackers for getting AWS/GCP/Azure access. The difference is that these API keys to your LLMs have the potential to create more harm for your organization.&lt;/p&gt;

&lt;p&gt;In practice, LLMjacking typically involves an attacker obtaining an API key through phishing, source code leaks, misconfigured environments, or exposed client-side code.&lt;/p&gt;

&lt;h3&gt;
  
  
  Good old phishing
&lt;/h3&gt;

&lt;p&gt;Despite increasingly sophisticated AI-assisted attacks, attackers still rely on one of the oldest tricks in the book: convincing someone to just hand over their credentials. Phishing campaigns remain a highly effective way to gain access to LLM resources, as these campaigns target people rather than technology.&lt;/p&gt;

&lt;p&gt;A well-crafted phishing page is probably the easiest way that most attackers would &lt;a href="https://www.darkreading.com/application-security/llm-hijackers-deepseek-api-keys" rel="noopener noreferrer"&gt;gain access to your credentials&lt;/a&gt;. All of the old tactics still work: creating a false sense of urgency or spoofing platform notifications, all of which are designed to pressure a user into acting quickly.&lt;/p&gt;

&lt;h3&gt;
  
  
  Bad cloud or application configurations
&lt;/h3&gt;

&lt;p&gt;Misconfigured cloud environments continue to be one of the easiest ways for attackers to obtain sensitive credentials, and LLM integrations are no exception. API keys are often &lt;a href="https://auth0.com/blog/openclaw-credential-problem/" rel="noopener noreferrer"&gt;stored in environment variables, configuration files&lt;/a&gt;, container images, CI/CD pipelines, or logging systems that were never meant to be publicly accessible. Overly permissive S3 buckets, an exposed Kubernetes dashboard, or &lt;a href="https://krebsonsecurity.com/2025/05/xai-dev-leaks-api-key-for-private-spacex-tesla-llms/" rel="noopener noreferrer"&gt;a poorly secured Git repository&lt;/a&gt; can hand attackers everything they need without requiring them to exploit a vulnerability directly.&lt;/p&gt;

&lt;p&gt;The speed at which LLM integrations are being deployed in the modern tech stack makes the potential impact of this attack vector even worse. Teams will frequently prioritize function over security best practices. This is exactly how credentials end up getting leaked, giving potential attackers free, unadulterated access to your LLMs.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Monitor and Detect LLMjacking Attacks?
&lt;/h2&gt;

&lt;p&gt;Detecting an LLMjacking incident is less about spotting a single obvious breach (although you should still be on the lookout for those) and more about identifying unusual patterns of usage.&lt;/p&gt;

&lt;p&gt;Stolen API keys are often used in ways that mimic legitimate usage, which could make it harder for traditional security monitoring tools to spot the anomalies.&lt;/p&gt;

&lt;h3&gt;
  
  
  Baseline your organization's LLM usage first
&lt;/h3&gt;

&lt;p&gt;Before you can detect abnormal behavior, you need to know what "normal" looks like for your organization. This means establishing a baseline of API request volumes, token consumption, and common API endpoints. This baseline should also be established across different time periods. Do you normally have usage spikes on month-end? What about every second Tuesday?&lt;/p&gt;

&lt;p&gt;A solid baseline can help distinguish between organic usage changes and potential abuse. This baseline should be used to constantly compare against current usage patterns, and anomalies should be investigated as soon as possible to determine whether it was legitimate usage spikes or something more nefarious.&lt;/p&gt;

&lt;h3&gt;
  
  
  Monitor billing usage alerts
&lt;/h3&gt;

&lt;p&gt;A billing usage alert will probably be the first sign of something other than "normal" happening inside your environment. If attackers are blending in and abusing your LLMs in a "&lt;a href="https://www.cloudflare.com/learning/ddos/ddos-low-and-slow-attack/" rel="noopener noreferrer"&gt;low and slow&lt;/a&gt;" manner, you might not be able to pick it up.&lt;/p&gt;

&lt;p&gt;However, most attackers will probably try to use your LLM resources as much as possible, for fear of losing access before they have been able to do what they need to do. This will inevitably trigger billing usage alerts, in which case, you should investigate and act as soon as possible.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Defend Against LLMjacking?
&lt;/h2&gt;

&lt;p&gt;Defending against LLMjacking is largely about &lt;a href="https://auth0.com/blog/how-to-fix-five-critical-ai-agent-security-risks/" rel="noopener noreferrer"&gt;making the credentials harder to obtain&lt;/a&gt; in the first place. Since the attack typically relies on valid API keys rather than exploiting the model itself, traditional firewalls and other security hardware do not really feature here. Instead, effective defense relies on a combination of strong credential management, tight access controls, and continuous visibility into how those credentials are being used across your systems.&lt;/p&gt;

&lt;h3&gt;
  
  
  Enforce good credential hygiene
&lt;/h3&gt;

&lt;p&gt;This is one of the most effective ways to limit the impact of an LLMjacking incident. It reduces the window of opportunity an attacker has if one of your keys is exposed. Regularly rotating API keys ensures that any leaked credentials have a limited lifespan.&lt;/p&gt;

&lt;p&gt;Workload-specific keys add another important layer of containment. Instead of &lt;a href="https://auth0.com/blog/secure-ai-stop-managing-api-keys-by-hand/" rel="noopener noreferrer"&gt;one shared credential granting broad access&lt;/a&gt; across multiple services, each application, service, or environment gets its own &lt;a href="https://auth0.com/blog/why-ai-agents-need-their-own-permission-model/" rel="noopener noreferrer"&gt;narrowly scoped identity&lt;/a&gt;. This should make abuse much easier to detect and isolate, since unusual usage can be traced back to a specific workload rather than blending into general traffic.&lt;/p&gt;

&lt;p&gt;Workload-specific keys also have the added benefit of reducing the blast radius of a compromised key. These keys should only have access to specific endpoints for a specific set of operations.&lt;/p&gt;

&lt;h3&gt;
  
  
  Apply the principle of least privilege
&lt;/h3&gt;

&lt;p&gt;Workload-specific keys are one way of achieving the &lt;a href="https://en.wikipedia.org/wiki/Principle_of_least_privilege" rel="noopener noreferrer"&gt;principle of least privilege&lt;/a&gt;. Applying the principle of least privilege is really about resisting the temptation to give every integration a "just in case" level of access. If a single API key can reach multiple models, environments, or downstream systems, whoever steals it effectively inherits far more capability than that key should ever have had in the first place.&lt;/p&gt;

&lt;p&gt;These same principles should be applied to your human users as well. Does Carol from marketing really need access to production prompts, customer data pipelines, and your fine-tuned legal summarization model? Probably not. Again, by tightly scoping permissions to specific workloads, endpoints, and even models, you ensure that a compromised key will limit the capabilities an attacker might gain from that key.&lt;/p&gt;

&lt;h3&gt;
  
  
  Basic security principles
&lt;/h3&gt;

&lt;p&gt;Sometimes we forget that the basics can also help to protect you from LLMjacking attacks. LLMjacking is not a fancy new exploit that threatens to bring down your entire organization. The following points will help strengthen your overall security posture and help you detect and prevent LLMjacking incidents.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use a proper secrets management platform, like &lt;a href="https://www.hashicorp.com/en/products/vault" rel="noopener noreferrer"&gt;Hashicorp Vault&lt;/a&gt;. This is especially useful for automating the rotation of workload-specific keys so as to minimize the usefulness of a compromised key.&lt;/li&gt;
&lt;li&gt;GitHub enables push protection by default on all repositories, blocking commits containing secrets before they ever reach your codebase. Make sure it has not been disabled in your repository settings. This does not mean secrets cannot slip through. If that does happen, treat that secret as compromised and rotate it immediately.&lt;/li&gt;
&lt;li&gt;Centralize your audit and access logs, for example, using a &lt;a href="https://en.wikipedia.org/wiki/Security_information_and_event_management" rel="noopener noreferrer"&gt;SIEM&lt;/a&gt; solution. This can help to create your initial baseline as well as monitor for anomalies, all from a centralized location.
## LLMjacking Is New; The Vulnerabilities It Exploits Are Not
Resource hijacking is a familiar story to many a cybersecurity professional. Attackers steal credentials and exploit them for their own gain at the victim's expense. LLMjacking is just one of the newer chapters in that story, and one with potentially higher stakes than what came before it. With LLMjacking, attackers get the same level of access as your systems and employees. This can lead to financial harm and risks exposing your company's and customers' sensitive data.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This threat is particularly concerning because of how deeply LLMs are embedded in modern tech stacks. They are no longer isolated tools, but components that influence decisions, automate processes, and interact with data in real time.&lt;/p&gt;

&lt;p&gt;Defending against LLMjacking does not require newfangled security mechanisms; it requires getting the basics right. Treat those API keys as high-value assets, limit their scope, and monitor their usage with intent. While the technology behind those keys is new, the weak points being exploited are well known and well understood.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>llm</category>
    </item>
  </channel>
</rss>
