Zenity Labs
aidefend-sf0006
Bring Your Own Agent: Exposed LLM Backends as Attacker AI Compute
- AI Infrastructure
- Autonomous Agents
- Resource Hijacking & Cost
Zenity Labs observed three distinct operators use exposed Ollama or LiteLLM endpoints between March and May 2026 without exploiting the server software. One sent a 140,000-character Strix prompt and actively retried against a live French auction site before Zenity blocked completion; one staged HexStrike AI with 150 tool definitions but assigned no live target; and one sent 18 Codex-shaped requests carrying an anti-safety web-auditor persona that Zenity assessed as manual web reverse-engineering work without a confirmed target. The flow preserves those different evidence bounds instead of forcing all three into one impact path.