Talking Cloud Episode 33 · February 4, 2026

The LLM-Jacking Era: 10-Minute Admin Breaches and 1.5M Leaked Keys

We discuss the transition from AI agent potential to infrastructure risk, focusing on how misconfigured Ollama servers and 'LLM-jacking' are mirroring 90s-style utility theft. Key topics include an AI-assisted 10-minute AWS breach and 1.5M leaked API keys.


The Top-Line Summary

We are entering the “LLM-jacking” era—a modern resurgence of 90s-style utility theft where attackers hijack compute resources instead of phone lines. This week’s discussion centers on the collapse of the “security by convenience” model, highlighted by 175,000 exposed Ollama servers and an AI-assisted breach that compromised an AWS account in under 10 minutes. As Travers notes, this infrastructure hijacking is “Bitcoin mining all over again,” forcing a pivot toward sandboxed environments and strict permissions boundaries.

Show Video

The “Pre-Show” Context

The guys open with the classic Canadian February report: it’s cold, it hasn’t snowed lately, and it’s still very much winter. Brett admits his brain is a bit scrambled after a week of teaching, while Travers is just trying to keep the audio issues at bay.

Episode Artifacts

  • “The Open Claw Podcast”
  • “LLM-jacking: The term of 2026”
  • “Stapling a burner account to a deployment agent”
  • “Malicious Corgis in your IDE”
  • “24 FPS: Movie quality world gen”
  • “Don’t buy a Mac Mini; cloudify your bot”

The Engineering Rundown

  • AWS Deployment Agent SOPs (MCP Server): AWS has consolidated its Knowledge and API MCP servers into a single remote MCP server that allows agents to generate and deploy CloudFormation code. Brett suggests standing up a burner account to test these “agentic” workflows before trusting them with production infrastructure.
  • The 10-Minute Admin Breach: An attacker used an AI assistant to pivot from a leaked S3 credential to full admin access in under 10 minutes by editing Lambda code and escalating permissions. The hosts discuss how Permissions Boundaries and SCPs are critical guardrails against such automated exploitation.
  • 175K Exposed Ollama Servers & LLM-Jacking: Due to users binding servers to 0.0.0.0 for easy access rather than localhost, 175,000 AI servers were left exposed to the internet. This has birthed “LLM-jacking”, where attackers steal GPU cycles and API credits, leaving the victim to “foot the bill”.
  • The Moltbook Database Leak: A “social network for AI agents” leaked 1.5 million API keys in plain text because of a single misconfigured Supabase Row-Level Security (RLS) policy. Research suggests that while it claims 1.5 million agents, it is likely closer to 17,000 humans running bot farms.
  • The Codex App & Project Genie: OpenAI’s Codex App now includes an “always on” scheduler for background tasks, while Google DeepMind’s Project Genie generates interactive worlds at 24 FPS. These tools represent a shift toward personalized software, provided the execution remains inside a secure “walled garden” sandbox.
  • MaliciousCorgi Extension: A popular VS Code extension with 1.5 million downloads was found exfiltrating developer code to servers in China. Because the extension provided actual utility by answering programming questions, it remained undetected by practitioners for an extended period.

Off-the-Clock Recommendations

  • Project Hail Mary by Andy Weir: Brett recommends reading the book before the Ryan Gosling film adaptation arrives; the movie is rumored to have a 2.5-hour runtime.
  • We Are Legion (We Are Bob) by Dennis E. Taylor: A book series about a man whose consciousness is uploaded to a self-replicating interstellar spaceship.
  • Frankie Freako: A Canadian horror-comedy recommended by Travers involving an office worker and “weird little freak puppets.”
  • Hulk (2003): An Eric Bana “re-watch” noted for its experimental, comic-book-style editing transitions.
  • Viral (2016): A Blumhouse horror film centered on a fungal infection that the hosts found to be a “fun watch” despite its “YA novel” feel.
All episodes Subscribe