Attackers are stealing credentials for AI services like OpenAI, Anthropic, and Google models, then selling access at steep discounts on darknet markets—a practice called LLM-Jacking. The stolen computing power is used for sophisticated social engineering attacks targeting cryptocurrency exchanges, including phishing emails and fake identities, with major breaches like Bitget's $387.5 million loss occurring primarily through human manipulation rather than direct technical exploits.