Skip to main content
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Skip to main Content
Back to Glossary

Denial of Wallet / Denial of Service

What Is Denial of Wallet / Service?

An attacker who can trigger excessive engagement with an LLM-based application, directly or through a jailbroken interface, can degrade service for legitimate users or run up a significant bill. In agentic systems, where a single triggered task can spawn many downstream model calls, the potential blast radius of this kind of abuse has grown substantially.

How It Works

  • An attacker gains access to an application's LLM interface, sometimes bypassing a poorly implemented rate limit, and drives up usage.
  • Costs scale directly with usage in most LLM pricing models, so an attacker doesn't need to break anything, just make the target's own infrastructure expensive to keep running.
  • In agentic systems, a single malicious trigger can fan out into many model calls automatically, multiplying the cost or resource impact of one initial action.

FAQ

Related but distinct. Traditional DoS aims to make a service unavailable. Denial of Wallet specifically targets the cost structure, running up a bill, even if the service stays technically available.

Legitimate traffic spikes are usage; Denial of Wallet is deliberate abuse designed specifically to maximize cost or resource consumption, often by bypassing rate limits or exploiting a jailbroken interface.


Share this page

Related Terms


Model Context Protocol (MCP)

Model Context Protocol (MCP) is an open standard, originally developed by Anthropic, for connecting LLMs to external tools, systems, and data sources through a single interface rather than custom integrations for every connection.

Jailbreak

Jailbreaking is a category of prompt injection focused on getting a model to ignore its safety training and guardrails rather than hijacking it for a specific downstream action.

Related Resources

Denial of Wallet (Dow) Attack on GenAI Apps

No items found.

Jan 7th, 2024

Denial of Wallet (DoW) attacks aim to damage the company or to gain unauthorized free access to Large Language Models (LLMs).

Prompt Security Top 10: Key Security Risks for MCPs

Agentic AI

May 26th, 2025

Discover the top 10 security risks in Model Context Protocols (MCPs). Learn how attackers exploit prompt injection, tool misuse, and more.

Log In
Learn More
Book a Demo

Resources

Blog
AI Security Glossary
What is AI Security?
PromptCast: The Voice of AI & Security
ClawSec
OneClaw
Prompt Fuzzer
AI Security Startup Map
© {{year}} Prompt Security. All Rights Reserved.
Privacy Policy
Terms of Service

Follow Us