A $950 botnet burns your AI credits while your site stays up

WraithTools sells x47.c, a Windows botnet whose AI drain mode sends billable requests straight to OpenAI and xAI until a victim's credits run out. The loss is not hypothetical: one stolen key burned about $600,000 of credits at METR in three weeks.

In this storyOpenAIxAI
Vincent JiangVincent Jiang · 2 min read
Share
The OpenAI logo and website seen through a magnifying glass on a bright purple screen
1 / 6Slide 1 of 6
OpenAI, one of the chat API providers the x47.c drain mode bills a victim's key against, under a magnifying glass.

A seller under the name WraithTools advertises x47.c, a Windows botnet with DDoS, credential theft, SOCKS5 proxies and an AI API drain mode. Qrator Labs documented the offer from the seller's advertisement, technical documentation and panel screenshots 12. A listing dated 3 August 2026 put the base package at $200, the DDoS add-on at $150 and the full arsenal at $950 23.

The full AI-drain botnet lists for $950

$0$200$400$600$800$1,000DDoS add-on$150Base package$200Full package$950
Data
Value
DDoS add-on$150
Base package$200
Full package$950
Advertised prices in US dollars for the x47.c botnet, from a seller listing dated 3 August 2026, as documented by Qrator Labs.1,3

The site stays up while the account runs dry

The control panel offers 18 attack methods, and the drain is not a flood. The operator supplies a victim's valid API key and a model name, and the bots send billable requests straight to OpenAI, xAI or any compatible chat API 13. The traffic never touches the victim's application, so the site stays reachable while the account behind it empties, and nothing filtered at the site's edge stops it 12. The attack class even has a name, denial of wallet 2. The seller pitches it as a service for kneecapping rivals' chatbots and "Jarvis-style systems," and notes that automatic top-ups keep the charges running after the balance hits zero 23.

Grok sits on both sides of the trade

The botnet's own persistence is outsourced to AI. An "AI stealth" module calls xAI's Grok to choose repairs from a predefined list, startup entries, scheduled tasks, Windows Defender exclusions, with local fallbacks when a model call fails; the operator enables it by pasting an xAI key into the build 13. The same vendor's model keeps the malware installed while its API is a named target of the drain. Grok 4.7 lists at $2 per million input tokens and $6 per million output 4, and every drain request bills the key owner at rates like those.

The meter has already run once

In March, attackers stole an API key from METR, the nonprofit that evaluates frontier models, and spent three weeks consuming credits worth about $600,000 56. Nobody noticed, because METR legitimately burns enormous token volumes and had no caps on spend 5. The credits had come free from the model provider, so METR paid nothing 6.

The fix is a spending cap, not a firewall

Qrator's guidance is dull and effective: revoke exposed keys, set spending limits, control automatic top-ups 23. Its own caveat matters more: anyone holding a valid key could script this without a botnet, and the advertised protection-bypass modes carry no test results 2. The platforms built the meter, priced the tokens and left the keys cheap. Watch whether spend caps become a default rather than an option.

How this brief was made

01Gathered & sourced389 channels · 1,247 articles▾

Agents swept 389 channels and ingested 1,247 articles, then de-duplicated and ranked them for signal.

02Verified & cross-validated6 claims · 38 data feeds▾
03Reviewed & edited1 human editor▾

One editor read the draft against the evidence, tuned the framing, and signed off before it shipped.

Become a contributor

Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.

Share

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio