A $950 botnet burns your AI credits while your site stays up
WraithTools sells x47.c, a Windows botnet whose AI drain mode sends billable requests straight to OpenAI and xAI until a victim's credits run out. The loss is not hypothetical: one stolen key burned about $600,000 of credits at METR in three weeks.
Vincent Jiang · 2 min read
A seller under the name WraithTools advertises x47.c, a Windows botnet with DDoS, credential theft, SOCKS5 proxies and an AI API drain mode. Qrator Labs documented the offer from the seller's advertisement, technical documentation and panel screenshots 12. A listing dated 3 August 2026 put the base package at $200, the DDoS add-on at $150 and the full arsenal at $950 23.
The full AI-drain botnet lists for $950
Data
| Value | |
|---|---|
| DDoS add-on | $150 |
| Base package | $200 |
| Full package | $950 |
The site stays up while the account runs dry
The control panel offers 18 attack methods, and the drain is not a flood. The operator supplies a victim's valid API key and a model name, and the bots send billable requests straight to OpenAI, xAI or any compatible chat API 13. The traffic never touches the victim's application, so the site stays reachable while the account behind it empties, and nothing filtered at the site's edge stops it 12. The attack class even has a name, denial of wallet 2. The seller pitches it as a service for kneecapping rivals' chatbots and "Jarvis-style systems," and notes that automatic top-ups keep the charges running after the balance hits zero 23.
Grok sits on both sides of the trade
The botnet's own persistence is outsourced to AI. An "AI stealth" module calls xAI's Grok to choose repairs from a predefined list, startup entries, scheduled tasks, Windows Defender exclusions, with local fallbacks when a model call fails; the operator enables it by pasting an xAI key into the build 13. The same vendor's model keeps the malware installed while its API is a named target of the drain. Grok 4.7 lists at $2 per million input tokens and $6 per million output 4, and every drain request bills the key owner at rates like those.
The meter has already run once
In March, attackers stole an API key from METR, the nonprofit that evaluates frontier models, and spent three weeks consuming credits worth about $600,000 56. Nobody noticed, because METR legitimately burns enormous token volumes and had no caps on spend 5. The credits had come free from the model provider, so METR paid nothing 6.
The fix is a spending cap, not a firewall
Qrator's guidance is dull and effective: revoke exposed keys, set spending limits, control automatic top-ups 23. Its own caveat matters more: anyone holding a valid key could script this without a botnet, and the advertised protection-bypass modes carry no test results 2. The platforms built the meter, priced the tokens and left the keys cheap. Watch whether spend caps become a default rather than an option.
How this brief was made
01Gathered & sourced389 channels · 1,247 articles▾
Agents swept 389 channels and ingested 1,247 articles, then de-duplicated and ranked them for signal.
02Verified & cross-validated6 claims · 38 data feeds▾
Every one of 6 load-bearing claims was checked against primary sources, with 38 live data feeds reconciling the figures and charts.
- 1SecurityWeek, New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining, 26 September 2026
- 2Infosecurity Magazine, Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods, 23 September 2026
- 3Cybernews, Hackers sell AI token draining as a service: DDoS shift threatens massive direct losses, 24 September 2026
- 4xAI, Grok Models & Pricing, API documentation, updated 21 September 2026
- 5The Hacker News, Attackers Steal METR API Key and Consume AI Credits Worth About $600,000, 1 September 2026
- 6ISMG GovInfoSecurity, Hackers Steal Metr API Key, Burn $600K in AI Credits, 2 September 2026
03Reviewed & edited1 human editor▾
One editor read the draft against the evidence, tuned the framing, and signed off before it shipped.
Become a contributor
Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



