AI credentials are entering the same criminal economy as browser sessions, cloud tokens, and developer secrets. METR disclosed a stolen model-provider key used for roughly $600,000 in credits. Unit 42 reported organizational credentials inserted into AI proxy “transfer stations” and nearly $1 million in charges. Together, those reports likely satisfy AlphaHunt’s two-incident forecast threshold—subject to one honest caveat: Unit 42’s affected organization is anonymous.
For defenders, the harder question is already settled. Password resets and MFA re-enrollment do not revoke every browser session, API key, gateway credential, or cloud identity reachable from an infected developer endpoint. The useful control model starts with the authority each credential carries, then joins per-key usage, source context, billing, account changes, and emergency revocation. Otherwise the laptop receives a clean image while the attacker keeps the working copy of its authority.
Read the forecast, evidence boundary, and practical 30-day test.