Skip to main content
Prompt Security from SentinelOne
  • AI Security Academy

    AI Security Academy

    Learn More
    Title of post

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    Learn More
    Title of post

    AI Security Glossary

    Explore some of the most common terms in AI Security

    Learn More
    Title of post

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    Learn More
    Title of post

    OneClaw

    Track and analyze OpenClaw deployments in your org

    Learn More
    Title of post

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Learn More
    Title of post

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Prompt Security from SentinelOne
  • AI Security Academy

    AI Security Academy

    Learn More
    Title of post

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    Learn More
    Title of post

    AI Security Glossary

    Explore some of the most common terms in AI Security

    Learn More
    Title of post

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    Learn More
    Title of post

    OneClaw

    Track and analyze OpenClaw deployments in your org

    Learn More
    Title of post

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Learn More
    Title of post

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Skip to main Content
Back to Glossary
Back to Glossary

Denial of Wallet / Denial of Service

What Is Denial of Wallet / Service?

An attacker who can trigger excessive engagement with an LLM-based application, directly or through a jailbroken interface, can degrade service for legitimate users or run up a significant bill. In agentic systems, where a single triggered task can spawn many downstream model calls, the potential blast radius of this kind of abuse has grown substantially.

How It Works

  • An attacker gains access to an application's LLM interface, sometimes bypassing a poorly implemented rate limit, and drives up usage.
  • Costs scale directly with usage in most LLM pricing models, so an attacker doesn't need to break anything, just make the target's own infrastructure expensive to keep running.
  • In agentic systems, a single malicious trigger can fan out into many model calls automatically, multiplying the cost or resource impact of one initial action.

FAQ

Related but distinct. Traditional DoS aims to make a service unavailable. Denial of Wallet specifically targets the cost structure, running up a bill, even if the service stays technically available.

Legitimate traffic spikes are usage; Denial of Wallet is deliberate abuse designed specifically to maximize cost or resource consumption, often by bypassing rate limits or exploiting a jailbroken interface.


Share this page

Related Terms


Model Context Protocol (MCP)
Learn More
Title of post

Model Context Protocol (MCP) is an open standard, originally developed by Anthropic, for connecting LLMs to external tools, systems, and data sources through a single interface rather than custom integrations for every connection.

Jailbreak
Learn More
Title of post

Jailbreaking is a category of prompt injection focused on getting a model to ignore its safety training and guardrails rather than hijacking it for a specific downstream action.

Related Resources

Learn More
Title of post

Denial of Wallet in AI: When Cost Exhaustion Becomes Downtime

AI Risks

Jan 7th, 2024

Denial of wallet attacks exploit AI's usage-based pricing to inflate costs or degrade service. See how AI agents raise the stakes and what stops it.

Learn More
Title of post
Learn More
Title of post

Prompt Security Top 10: Key Security Risks for MCPs

Agentic AI

May 26th, 2025

Discover the top 10 security risks in Model Context Protocols (MCPs). Learn how attackers exploit prompt injection, tool misuse, and more.

Learn More
Title of post
Prompt Security from SentinelOne
Log In
Log In
Learn More
Book a Demo

Resources

Blog
AI Security Glossary
What is AI Security?
PromptCast: The Voice of AI & Security
ClawSec
OneClaw
Prompt Fuzzer
AI Security Startup Map
© {{year}} Prompt Security. All Rights Reserved.
Privacy Policy
Terms of Service

Follow Us