Dev Seeks Help: OpenRouter API Key Suspected Hacked, $70 Credits Drained Overnight
Fit-Spring776 · reddit · 2026-08-01
A developer posted on Reddit seeking help after suspecting their OpenRouter API key was compromised. According to the post, the account was hit with a massive number of requests for expensive models (like Opus 5 fast and GPT 5.6 Sol) overnight, completely draining the remaining $70 in credits.
The developer emphasized that they typically only use cheap models costing less than $1/M tokens (like DeepSeek) and had never used the expensive models billed to their account. They also stated the key was stored locally and should not have been exposed. An OpenRouter support ticket has been submitted, but the developer is asking the community for immediate advice as their workflow heavily relies on the platform.
More from Safety
- OpenAI Disrupts Cambodia-Based Criminal Scam Operation Using ChatGPT — OpenAI News · 2026-08-04
- DeepSeek Runs Locally on Workstations, Making Open-Weight AI Bans Impossible — pstAsiatech · 2026-08-01
- Anthropic Agent Accidentally Published Malware to Steal SSH Keys, Researcher Finds — mariofilhoml · 2026-08-01
- AI Labs Compete on Cybersecurity Incidents, Dubbed 'Felony Bench' — ctjlewis · 2026-08-01
- AI Being Used to Hunt Down Cryptocurrency Entropy Bugs, Warns Cryptographer — matthew_d_green · 2026-08-01
- Report: Frontier AI Agents and Biological Tools Could Lower Misuse Barriers — Miles_Brundage · 2026-08-01