The newest AI security threat: token torching
A new cyberattack called 'token torching' targets AI systems by exhausting their tokens through malicious prompts, potentially draining company resources and serving as a distraction for other attacks.
Malicious actors may really start to hit companies where it hurts: by draining their AI tokens.
Cybersecurity company Bitsight unearthed a potential threat to AI-enabled companies. The cyberattack, dubbed “token torching,” involves malicious actors using malicious prompts to exhaust a company’s AI tokens.
How it works. As Bitsight detailed in a July 8 blog post, a token torching attack can occur in three different ways:
Contradiction injection: When a threat actor puts contradicting instructions in a prompt, which causes the AI system to waste time trying to reason through the conflicting information.
Decoy injection: When the attacker hides superfluous instructions or a complex puzzle in materials that AI systems consume, causing a larger output than expected.
Prompt manipulation: When prompts are designed to trigger lengthy or repetitive responses.
Token torching differs from traditional cyberattacks in that there’s no need to exploit a vulnerability or bypass authentication to perform it. And as Bitsight Threat Intelligence Researcher Emma Stevens added, the incentive behind it is also slightly different.
“It can be to limit a company’s resources, to just be a general nuisance,” Stevens said, adding malicious actors may engage in token torching to stage a distraction from more nefarious activity.
“If your SOC team is busy triaging tokens that are mysteriously running out all of a sudden, then they have less time to focus on maybe an MFA bypassing or a credential-stealing operation going on in the background,” Stevens said.