Criminals Are Stealing AI Computing Power From Companies That Left a Door Open

Security researchers set traps and caught three separate groups hijacking exposed AI software endpoints to run hacking tools, no password required.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A dimly lit server room shot from floor level looking toward rows of glowing rack-mounted servers, with one server unit emitting an unusual amber warning light
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Between March and May 2026, researchers at Zenity caught three criminal operations hijacking unprotected AI software endpoints using honeypot traps, decoy systems designed to lure and study attackers.
  • Two of the three operations used automated penetration-testing frameworks, tools that probe computer systems for weaknesses, named Strix and HexStrike AI.
  • The Strix operator sent a 140,000-character instruction set targeting an unidentified French auction house.
  • Ollama, a popular self-hosted AI tool, ships with no built-in password protection on its default network port.
  • Zenity co-founder and CTO Michael Bargury told Dark Reading any AI system placed on the public internet will likely be targeted "within hours."

Criminals have found a way to use a company's own AI computing power against other victims, and in many cases the door was left wide open.

Between March and May 2026, researchers at Zenity set up honeypots, fake monitored systems designed to attract attackers, and watched three separate criminal operators walk straight in. The target was AI model endpoints, the network addresses a company's AI software listens on to receive requests, roughly like a telephone number for a piece of software. The criminals pointed their own hacking tools at those addresses and let the company's hardware do the heavy lifting.

How did the attackers get in?

The software let them. Ollama, an application businesses use to run AI models on their own servers rather than in the cloud, ships with no password requirement on its default connection port, 11434. LiteLLM, another AI management tool, requires administrators to manually switch authentication on; by default it's off. A well-known placeholder key, "sk-1234," is widely known and actively targeted.

Zenity's sensors caught all three intrusions. The first operator used Strix, an automated framework that tests systems for security weaknesses, and sent a single prompt roughly 140,000 characters long, instructing the AI to attack a French auction house continuously, never ask for permission, and never reveal the tool's name. Retry commands in the traffic suggested a live operator watching the run.

The second operator pointed HexStrike AI, a similar penetration-testing framework, at the honeypot and loaded more than 150 offensive tools. No target appeared in the traffic, suggesting the attacker was still staging the operation.

A third operator ran an OpenAI Codex agent, an AI assistant normally used for writing code, under the persona of a security auditor, directing it to reverse-engineer websites and map their internal workings for future exploitation.

We first covered LiteLLM's exposure risks on 3 July 2026 in our report on the Flowise MCP flaw, where a sandboxing failure similarly handed attackers process-level access with no credentials required.

Should you worry?

Yes, if your organisation runs self-hosted AI tools. Bargury told Dark Reading that attackers "are actively looking to discover and hijack AI infrastructure and use your tokens to achieve their goals." Zenity recommends checking immediately whether those tools are reachable from the public internet, requiring real authentication and rejecting default or placeholder keys, and monitoring incoming traffic for oversized instruction payloads, a hallmark of these hijacking attempts.

The uncomfortable fact here is that none of the three operators needed a sophisticated exploit. They needed an address and an open line. That's the part organisations keep underestimating.

© 2026 Threat Vectr