Pillar Security Uncovers Criminal Networks Stealing AI Compute Resources
Pillar Security identified large-scale campaigns targeting exposed AI endpoints to steal and resell compute resources through a criminal marketplace.
Researchers at Pillar Security have identified large-scale criminal campaigns targeting exposed large language model (LLM) and Model Context Protocol (MCP) endpoints. A specific effort, titled Operation Bizarre Bazaar, employs a distributed bot infrastructure to scan for unauthenticated AI services, including vLLM and Ollama. These attackers exfiltrate data and steal compute resources to resell them at discounted rates via a criminal marketplace known as The Unified LLM API Gateway.
The marketplace is hosted on bulletproof infrastructure in the Netherlands and marketed through Telegram and Discord. Pillar Security recorded 35,000 attack sessions over a two-week period. Security experts warn that these exposed endpoints can act as pivot vectors, allowing attackers to move from AI services into internal corporate systems.
To mitigate these risks, researchers recommend enabling authentication on all LLM endpoints, auditing MCP server exposure, and implementing rate limiting. Industry leaders emphasize that the low technical barrier for exploitation could lead to catastrophic impacts if organizations do not prioritize securing protocol interfaces and providing dedicated AI risk training for users.