GitHub, Anthropic and Uber: Cybersecurity Tokenomics: Denial of Wallet Attacks

GitHub, Anthropic and Uber: Cybersecurity Tokenomics: Denial of Wallet Attacks

AI Token Consumption Spirals Out of Control: The Rise of "Denial of Wallet" Attacks

In 2026, enterprises faced an unexpected crisis as AI adoption outpaced cost controls, leading to runaway spending and a new cybersecurity threat: denial-of-wallet attacks. Companies like Uber exhausted their annual AI budgets by April, while one unnamed organization racked up a $500 million bill in a single month after failing to set spending limits on Anthropic’s Claude. The shift from fixed-subscription models to pay-as-you-go billing coupled with the rise of autonomous AI agents has turned token consumption into a financial and security liability.

Why Costs Are Spiraling

Unlike traditional machine learning (ML) or human-operated chatbots, autonomous AI agents operate continuously, resending entire task histories (context) with each step. Errors, retries, and iterative loops cause token usage to balloon unpredictably sometimes by 30x or more for identical tasks. A single agent stuck in a "thought loop" can waste vast resources on trivial work, while multi-agent systems compound the problem by multiplying context exchanges.

The New DDoS: Denial of Wallet

Attackers are exploiting this unpredictability to financially cripple organizations. By flooding AI systems with malicious or overly complex requests, they trigger excessive token consumption. For example:

  • GitInject attacks on GitHub could cost victims $111 per incident and burn 400 minutes of GitHub Actions before defenses activate.
  • "OverThink" exploits demonstrated how a benign prompt could inflate token usage by 46x while bypassing security filters.
  • Gartner estimates a single LLM-powered support request costs $3 making mass-generated attacks a low-effort, high-impact threat.

The OWASP Top 10 for LLMs (2026) now ranks unbounded token consumption (LLM06) as a top risk, explicitly warning of denial-of-wallet attacks that drain budgets before anomalies are detected.

The Root of the Problem

Three generations of AI systems consume resources differently:

  1. Classical ML: Predictable, low-cost, fixed budget.
  2. LLM chatbots: Costs scale with user activity, manageable via licenses.
  3. Autonomous agents: No cost ceiling token usage grows exponentially with task complexity, errors, and retries.

Without FinOps-style cost controls (common in cloud and telecom), companies only discover the true cost of AI processes after the fact. The probabilistic nature of generative AI further complicates forecasting, leaving organizations vulnerable to both accidental overspending and targeted attacks.

The shift to AI agents has exposed a critical gap: enterprises lack the tools to monitor, predict, or cap token consumption making them prime targets for a new breed of financial sabotage.

Source: https://www.kaspersky.com/blog/tokenomics-ai-cost-ddos/56455/

Uber AI cybersecurity rating report: https://www.rankiteo.com/company/uber-ai-labs

GitHub cybersecurity rating report: https://www.rankiteo.com/company/github

Anthropic cybersecurity rating report: https://www.rankiteo.com/company/anthropicresearch

"id": "UBEGITANT1790187944",
"linkid": "uber-ai-labs, github, anthropicresearch",
"type": "Cyber Attack",
"date": "4/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'name': 'Uber', 'type': 'Enterprise'},
                       {'name': 'Unnamed organization (Anthropic’s Claude '
                                'user)',
                        'type': 'Enterprise'}],
 'attack_vector': ['Malicious or overly complex requests',
                   'GitInject attacks',
                   'OverThink exploits'],
 'date_detected': '2026',
 'description': 'In 2026, enterprises faced an unexpected crisis as AI '
                'adoption outpaced cost controls, leading to runaway spending '
                'and a new cybersecurity threat: denial-of-wallet attacks. '
                'Companies like Uber exhausted their annual AI budgets by '
                'April, while one unnamed organization racked up a $500 '
                'million bill in a single month after failing to set spending '
                'limits on Anthropic’s Claude. The shift from '
                'fixed-subscription models to pay-as-you-go billing coupled '
                'with the rise of autonomous AI agents has turned token '
                'consumption into a financial and security liability.',
 'impact': {'downtime': '400 minutes of GitHub Actions per GitInject incident',
            'financial_loss': ['$500 million in a single month (unnamed '
                               'organization)',
                               '$111 per GitInject incident',
                               '$3 per LLM-powered support request'],
            'operational_impact': 'Exhaustion of annual AI budgets, '
                                  'unpredictable token consumption, financial '
                                  'liabilities',
            'systems_affected': ['AI systems',
                                 'Autonomous AI agents',
                                 'GitHub Actions']},
 'lessons_learned': 'Enterprises lack tools to monitor, predict, or cap token '
                    'consumption, leaving them vulnerable to accidental '
                    'overspending and targeted financial sabotage. The shift '
                    'to autonomous AI agents has exposed critical gaps in cost '
                    'controls and security measures for AI systems.',
 'motivation': ['Financial sabotage', 'Exploiting AI system vulnerabilities'],
 'post_incident_analysis': {'corrective_actions': ['Implement spending limits '
                                                   'on AI systems',
                                                   'Adopt FinOps practices for '
                                                   'AI cost management',
                                                   'Enhance monitoring for '
                                                   'token consumption '
                                                   'anomalies',
                                                   'Follow OWASP Top 10 for '
                                                   'LLMs guidelines'],
                            'root_causes': ['Shift from fixed-subscription to '
                                            'pay-as-you-go billing',
                                            'Rise of autonomous AI agents with '
                                            'unbounded token consumption',
                                            'Lack of FinOps-style cost '
                                            'controls for AI systems',
                                            'Probabilistic nature of '
                                            'generative AI complicating '
                                            'forecasting']},
 'recommendations': 'Implement FinOps-style cost controls for AI systems, set '
                    'spending limits on pay-as-you-go billing models, enhance '
                    'monitoring for token consumption anomalies, and adopt '
                    'OWASP Top 10 for LLMs guidelines to mitigate '
                    'denial-of-wallet risks.',
 'references': [{'source': 'Gartner'},
                {'source': 'OWASP Top 10 for LLMs (2026)'}],
 'title': 'Denial of Wallet Attacks: AI Token Consumption Spirals Out of '
          'Control',
 'type': 'Denial of Wallet Attack',
 'vulnerability_exploited': 'Unbounded token consumption (LLM06), lack of cost '
                            'controls on AI systems, pay-as-you-go billing '
                            'models'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.