Saturday, 3 October 2026

Demystifying Password Manager Cryptography and Vault Recovery: An IT Learner’s Guide

 

1. Introduction to Digital Vault Security

Modern password managers rely on a foundational security framework known as Zero-Knowledge Architecture. In a zero-knowledge model, vault payload decryption keys are derived entirely on the client side—meaning directly on the user's local device. As a result, cloud service providers have zero technical capability to view, access, or decrypt stored user credentials on their servers.

To maintain this strict zero-knowledge guarantee across complex, multi-device workflows, a robust password management ecosystem relies on three critical technical pillars:

  • Symmetric Encryption: Protects data at rest by locking sensitive vault payloads using high-strength cryptographic cyphers.
  • Key Derivation Functions (KDFs): Strengthen human passphrases by transforming low-entropy passwords into high-entropy cryptographic keys engineered to resist brute-force cracking.
  • Recovery Protocols: Restores access during emergency lockouts or user incapacitation without exposing master passwords or compromising underlying zero-knowledge guarantees.

Understanding how these primitives work together is essential when auditing an enterprise security posture. IT professionals must look beyond vendor marketing claims to evaluate how platforms defend sensitive credentials against offline GPU/ASIC cracking, network interception, database exfiltration, and administrative compromise.

With these architectural foundations in place, we turn first to the symmetric encryption cyphers used to safeguard digital vaults at rest.

2. Symmetric Encryption Cyphers: AES-256-GCM vs. XChaCha20

Symmetric encryption ensures that digital vault payloads remain confidential and tamper-proof when stored locally or synchronised across cloud infrastructure. Modern password managers primarily implement two main cipher standards: Advanced Encryption Standard (AES-256) and XChaCha20.

AES-256-GCM (and AES-256-CBC): AES-256 represents the established NIST baseline standard for digital vault protection. 1Password employs AES-256-GCM (Galois/Counter Mode), an Authenticated Encryption with Associated Data (AEAD) cypher. AEAD provides both data confidentiality and cryptographic integrity verification, preventing ciphertext tampering. Bitwarden utilises AES-256-CBC (Cipher Block Chaining) wrapped with HMAC-SHA256 to achieve explicit integrity verification. AES-256 relies heavily on dedicated hardware AES acceleration (such as AES-NI instructions) present in modern desktop and server processors for high-speed operation.

XChaCha20 NordPass diverges from legacy NIST block cyphers by deploying XChaCha20, a modern stream cipher from the ChaCha family. XChaCha20 utilises a 256-bit key and an extended 192-bit nonce (number used once). This extended nonce size virtually eliminates nonce-reuse vulnerabilities that can compromise standard ciphers under high volume. Technically, XChaCha20 offers key performance advantages: it is inherently resistant to side-channel and timing attacks, and it executes significantly faster in software on mobile architectures lacking dedicated hardware AES acceleration blocks.

Cryptographic Primitive

Cipher Type

Key & Nonce Size

Technical Advantages

Primary Implementers

AES-256-GCM

Authenticated Block Cipher (GCM)

256-bit Key, Standard Nonce

AEAD confidentiality and integrity verification; heavily optimized via hardware AES acceleration

1Password

AES-256-CBC / HMAC-SHA256

Block Cipher (CBC) with HMAC

256-bit Key

Established NIST baseline standard; explicit integrity checks via HMAC-SHA256

Bitwarden

XChaCha20

Stream Cipher

256-bit Key, 192-bit Nonce

Inherently resistant to side-channel/timing attacks; faster software execution on non-accelerated mobile devices; 192-bit nonce eliminates reuse risks

NordPass

Learner Insight ("So What?")

When evaluating encryption cyphers, an IT professional must balance enterprise compliance requirements against platform hardware execution. AES-256 is an established NIST standard, making it mandatory for organisations operating under strict regulatory compliance frameworks (such as FIPS or FedRAMP). Conversely, modern stream cyphers like XChaCha20 offer superior software execution on mobile processors lacking hardware AES acceleration while providing native resistance to timing side-channel attacks.

While symmetric cyphers lock the vault payload at rest, the cryptographic security of the vault depends entirely on how user passphrases are converted into encryption keys.

3. Key Derivation Functions (KDFs): PBKDF2 vs. Argon2id

Key Derivation Functions (KDFs) transform user-provided, human-readable passphrases into high-entropy cryptographic keys. Their primary objective is to introduce controlled computational and memory overhead, making offline dictionary and brute-force attacks computationally infeasible.

PBKDF2-HMAC-SHA256 Password-Based Key Derivation Function 2 (PBKDF2) enforces key stretching by running a pseudorandom function repeatedly over an input passphrase. 1Password configures PBKDF2-HMAC-SHA256 to 650,000 iterations, while Bitwarden sets its default to 600,000 iterations. PBKDF2 relies entirely on computational delay (CPU iteration counts) to slow down password guessing.

Argon2id Argon2id is a state-of-the-art KDF natively deployed by NordPass across all subscription tiers and offered as an opt-in configuration in Bitwarden. Configured with a baseline of 64 MB of RAM allocation and 3 processing iterations, Argon2id combines Argon2i (optimized to resist side-channel timing attacks) with Argon2d (optimized to resist GPU/ASIC cracking). Unlike PBKDF2, Argon2id enforces a dual defense mechanism that pairs computational processing with strict memory hardness.

Threat Model Insight: CPU-Bound vs. Memory-Hard KDFs

Standard CPU-bound KDFs like PBKDF2 rely purely on computational processing loops. Attackers using custom GPU clusters or Application-Specific Integrated Circuits (ASICs) can execute billions of PBKDF2 attempts per second by running thousands of computational cores in parallel.

In contrast, memory-hard KDFs like Argon2id require high dedicated RAM allocation (e.g., 64 MB) for every parallel hashing attempt. This high memory requirement starves hardware cracking rigs of memory bandwidth, rendering massive GPU/ASIC parallel brute-force campaigns mathematically and economically impractical.

Understanding how single passphrases are stretched into cryptographic keys lays the groundwork for evaluating advanced multi-secret authentication models.

4. Authentication Architecture: Single-Secret vs. Dual-Key (1Password 2SKD)

Password management systems differ fundamentally in how user inputs derive master decryption keys and authenticate client sessions with cloud backends.

Single-Secret Models

Platforms such as Bitwarden, NordPass, and LastPass rely on single-secret derivation architectures. In these models, the master decryption key and network authentication proofs are derived solely from a single user input—the master password—supplemented at the network transport layer by multi-factor authentication (MFA).

1Password 2SKD & Dual-Key Model

1Password implements a Two-Secret Key Derivation (2SKD) framework. Rather than relying on a master password alone, 1Password combines the user's password with a cryptographically random, client-generated 128-bit Secret Key. This Secret Key is created locally during account setup, stored strictly on local user devices (or synchronised via secure platform keychains such as Apple iCloud Keychain), and is never transmitted to 1Password's servers.

The 2SKD authentication and key derivation workflow follows these exact sequential steps:

  1. Local Secret Generation: During account registration, the client device locally generates a 128-bit Secret Key and prompts the user to create a master account password.
  2. Dual-Secret Input Combination: The client combines the user's master password with the offline 128-bit Secret Key on the local device.
  3. PBKDF2 Key Stretching: Both inputs are processed together through PBKDF2-HMAC-SHA256 (calibrated to 650,000 iterations) to derive high-entropy master key material.
  4. Key Material Separation: The output material splits into two independent cryptographic keys:
    • Account Unlock Key (AUK): Retained locally to decrypt the user's personal keyset and vault payloads.
    • Secure Remote Password (SRP) Secret: Used to initialise zero-knowledge network authentication.
  5. Zero-Knowledge Network Authentication: The client and server execute mutual authentication using the SRP protocol over HTTPS. This establishes an encrypted tunnel, authenticating the client session without ever transmitting raw passwords, Secret Keys, or master decryption keys over the network.

Programmatic Authentication in DevOps: Service Accounts

1Password extends its 2SKD dual-key security model to automated machine workflows via Service Accounts. Machine authentication presents a challenge: automated systems cannot enter a human master password. To solve this without compromising security, 1Password generates a serialized, Base64 URL-encoded JSON Web Token (JWT) prefixed with ops_.

This token contains the client-derived Account Unlock Key (AUK), the Secret Key, and the SRP secret serialised into a single string:

ops_eyJlbWFpbCI6InNlcnZpY2VAYWNjb3VudC5sY2wiLCJtdWsiOnsiYWxnIjoiQTI1NkdDTSIsImsiOiJNNFZQZkljOFZ..."

The ops_ prefix allows automated secret scanners (such as GitGuardian) to identify and flag accidentally committed service account tokens in source code repositories. When deployed in code pipelines, the token executes client-side key derivation locally to decrypt assigned environment vaults without storing unencrypted credentials in source code or server environments.

Learner Insight ("So What?")

In a single-secret system, if an adversary exfiltrates an encrypted cloud vault database, the security of the vaults depends entirely on the strength of user master passwords against offline GPU cracking. Under 1Password’s 2SKD model, even if an attacker exfiltrates the entire cloud database, cracking a vault payload is mathematically impossible without physical or local access to the user's offline 128-bit Secret Key.

Robust authentication models prevent unauthorised access during standard operations, but IT managers must also evaluate how platforms handle emergency access when credentials are lost.

5. Emergency Recovery and Digital Legacy Protocols

A key challenge in zero-knowledge security is digital legacy and emergency access: restoring vault data when a user is incapacitated or forgets credentials, without creating a backdoor for attackers or cloud administrators.

Bitwarden Asymmetric Public-Key Recovery

Bitwarden utilises an asymmetric public-key exchange between a vault owner (granter) and a trusted contact (grantee). The owner's user key is encrypted client-side with the grantee's public key and stored on the server. The owner configures the access scope (View-Only or Account Takeover) and sets a mandatory waiting period (ranging from 1 to 90 days).

When the grantee requests emergency access, the vault owner receives an email notification and can manually deny access during the waiting window. If the waiting period expires without owner denial, the server releases the encrypted key payload to the grantee, who decrypts it using their own master key.

1Password Emergency Kit & Administrative Re-Encryption

For individual accounts, 1Password provides an offline PDF Emergency Kit containing the user's account email, master password entry line, 128-bit Secret Key, and setup QR code.

For Family and Enterprise organisations, 1Password uses administrative re-encryption via public-key cryptography:

  1. Vault Key Allocation: At vault creation, each vault key is encrypted with the public key of a dedicated Recovery Group and uploaded to the server.
  2. Recovery Request: A locked-out user requests a reset and generates a new account password, Secret Key, and public/private keypair on their local client.
  3. Admin Key Decryption: An authorised administrator uses the Recovery Group's private key to decrypt the vault keys associated with the locked user's accounts.
  4. Re-Encryption & Delivery: The administrator re-encrypts those vault keys using the user's new public key and uploads them to the server. At no point in this workflow can administrators view the user's master password or unencrypted vault contents.

LastPass & NordPass Emergency Protocols

LastPass implements emergency access via public-key delegation. Users assign trusted emergency contacts who can request vault access. A configurable delay period (e.g., several days) initiates upon request; if the vault owner does not reject the request before the timer expires, the contact receives the decrypted vault key.

NordPass utilizes zero-knowledge contact delegation. Account owners designate trusted contacts within the platform. When an emergency contact requests access, access is granted following owner verification or the expiration of designated waiting terms, ensuring data is decrypted strictly on the recipient's local device.

Ephemeral Link Cryptography Mechanics (Bitwarden Send)

Beyond full account recovery, platforms also support zero-knowledge ephemeral sharing (e.g., Bitwarden Send). Bitwarden Send places the payload decryption key directly into the browser URL anchor fragment (#):

https://send.bitwarden.com/#send-id/decryption-key

Under standard HTTP specifications, the anchor fragment (#) is processed exclusively client-side by the browser and is never transmitted over the network to the server during HTTP GET requests. The server receives only the send-id, returning the raw, encrypted payload. The browser then extracts the decryption key from the local URL anchor fragment to decrypt the payload locally in memory, establishing a zero-knowledge data transfer mechanism.

Password Manager

Recovery Feature Name

Cryptographic Execution / Mechanism

User / Admin Workflow Steps

Bitwarden

Asymmetric Public-Key Emergency Access

Vault key is encrypted client-side using the grantee's public key and stored on the server until requested.

1. Grantee requests access.<br>2. Configurable wait window (1–90 days) initiates.<br>3. Owner receives alert and can deny request.<br>4. If unhandled, grantee decrypts vault key via their own master key.

1Password

Emergency Kit & Administrative Re-Encryption

Offline PDF contains 128-bit Secret Key; business/family vaults are encrypted with Recovery Group public keys.

Individual: User imports Secret Key from offline PDF.<br>Admin: User generates new keypair → Admin uses Recovery Group private key to decrypt vault keys → Admin re-encrypts keys with user's new public key.

NordPass

Emergency Contact Access

Zero-knowledge emergency contact access delegation workflows.

1. Owner designates trusted contact.<br>2. Contact requests emergency access.<br>3. Access is granted following verification and expiration of designated wait terms.

LastPass

Legacy Emergency Access

Public-key access delegation mechanics for trusted emergency contacts.

1. Owner assigns emergency contact.<br>2. Contact requests vault access.<br>3. Specified delay period expires without owner rejection.<br>4. Designated access is granted to contact.

Synthesising these cryptographic primitives, key derivation functions, and recovery mechanics allows us to build an actionable decision framework for IT evaluation.

6. Architectural Summary & IT Learner Decision Framework

Evaluating a password management platform requires analysing how symmetric ciphers, key derivation functions, authentication protocols, and recovery mechanisms work together as a complete system:

  1. Legacy Standards vs. Modern Primitives: Established standards like AES-256-GCM and PBKDF2 offer proven compliance (FIPS/FedRAMP) and hardware acceleration. Modern primitives like XChaCha20 and Argon2id provide optimised software performance on mobile architectures and protection against GPU/ASIC brute-force cracking.
  2. Single-Secret vs. Dual-Key Models: Single-secret systems rely entirely on master password entropy and network MFA. Dual-key architectures (like 1Password 2SKD) add an offline, device-bound secret key to protect vaults against offline cracking even if cloud databases are exfiltrated.
  3. Zero-Knowledge Recovery: Cryptographic emergency recovery must use asymmetric key re-encryption or offline key packages to ensure admins and service providers never gain unauthorised access to vault payloads.

Operational Realities of Self-Hosting

While self-hosting (supported natively by Bitwarden) provides total data sovereignty, IT teams must evaluate its operational requirements:

  • Infrastructure Overhead: Requires containerised orchestration (Docker or Kubernetes) and database maintenance.
  • Administrative Maintenance: Adds an estimated 20% to 40% operational overhead for patch management, backup verification, and network security.
  • Licensing Requirements: Self-hosting eliminates public cloud hosting but still requires paid Enterprise seat licensing ($6.00/user/month) to unlock business capabilities like SSO identity federation and SCIM directory provisioning.

IT Learner Checklist: Cryptographic Health Audit

When auditing a password management system's technical security posture, evaluate these three core criteria:

  • [ ] Metadata Encryption Scope: Verify whether the platform executes end-to-end client-side encryption across the entire vault structure—including target site URLs, item titles, secure notes, custom fields, and organisational folder trees. As demonstrated in the 2022 LastPass breach, leaving metadata (such as URLs and folder structures) unencrypted in cloud backups allows attackers to map user digital footprints and execute targeted spear-phishing campaigns despite passwords remaining encrypted.
  • [ ] KDF Memory Hardness: Assess whether the key derivation layer deploys memory-hard algorithms (such as Argon2id with 64 MB+ RAM allocation) or high iteration counts (600,000+ iterations for PBKDF2) to starve parallel GPU/ASIC hardware cracking rigs of memory bandwidth.
  • [ ] Emergency Access Cryptography: Confirm that account recovery processes rely on asymmetric public-key re-encryption or client-side emergency kits, ensuring that administrators or cloud servers cannot decrypt vault payloads or view master passwords.

Friday, 2 October 2026

yt-dlp/yt-dlp: A feature-rich command-line audio/video - Cheat Sheet

s 


Here is a comprehensive command cheat sheet for yt-dlp, categorised by common tasks and workflows:





1. Basic Downloading & Format Inspection

  • Download best available quality (default):
yt-dlp "URL"

*(Downloads the best video and audio streams and automatically merges them using FFmpeg)*[1].

  • List all available video/audio formats:
yt-dlp -F "URL"

*(Displays a table with format IDs, resolutions, codecs, and file sizes)*[3].

  • Download a specific format by ID:
yt-dlp -f 137+140 "URL"

(Downloads video format 137 and audio format 140 *and merges them)*[3].

 

 

 

  • Cap video quality at 1080p:
yt-dlp -f "bv*[height&lt;=1080]+ba/b[height&lt;=1080]" "URL"

*(Downloads the best video stream up to 1080p combined with the best audio)*[3][6].

  • Force output container to MP4:
yt-dlp -f "bv*[ext=mp4]+ba[ext=m4a]/b[ext=mp4]" --merge-output-format mp4 "URL"

*(Selects MP4-compatible video and audio streams and forces an MP4 output container)*[6][8].

  • Download the smallest file size:
yt-dlp -S "+size" "URL"

*(Sorts formats by ascending file size)*[3][8].


2. Audio Extraction

yt-dlp -x "URL"

*(Strips the video and leaves the original audio file like Opus or AAC without re-encoding)*[8].

  • Extract audio and convert to MP3:
yt-dlp -x --audio-format mp3 "URL"

*(Converts extracted audio into MP3 format)*[3][9].

  • Extract maximum quality MP3 with embedded cover art & metadata:
yt-dlp -x --audio-format mp3 --audio-quality 0 --embed-thumbnail --embed-metadata "URL"

(Sets VBR audio quality to best ( 0 *) and embeds thumbnail image as cover art along with metadata tags)*[10].


3. Playlists & Channels

  • Download an entire playlist or channel:
yt-dlp "PLAYLIST_URL"

*(Downloads all videos in a playlist or channel URL)*[3].

  • Download a specific range of playlist items:
yt-dlp --playlist-start 10 --playlist-end 20 "URL"

*(Downloads items 10 through 20)*[14].

  • Skip previously downloaded items (Archive file):
yt-dlp --download-archive archive.txt "URL"

(Saves video IDs to archive.txt *and skips any previously logged videos on subsequent runs)*[3][15].


4. Custom Output Filenames & Templates

  • Use video title only:
yt-dlp -o "%(title)s.%(ext)s" "URL"

*(Omits the default video ID suffix)*[3][16].

yt-dlp -o "%(upload_date&gt;%Y-%m-%d)s - %(title)s.%(ext)s" "URL"

*(Formats upload dates nicely in the filename)*[16][17].

  • Organise playlists into structured folders:
yt-dlp -o "%(playlist)s/%(playlist_index)s - %(title)s.%(ext)s" "URL"

*(Creates a subfolder named after the playlist and prefixes filenames with their index number)*[16].


5. Subtitles & Metadata

yt-dlp --list-subs "URL"

*(Lists all manual and auto-generated subtitle tracks)*[17][18].

  • Download and embed English subtitles:
yt-dlp --embed-subs --sub-lang en "URL"

*(Embeds English subtitles directly into MP4 or MKV files)*[3][18].

  • Embed metadata, thumbnail, and chapter markers:
yt-dlp --embed-metadata --embed-thumbnail --embed-chapters "URL"

*(Embeds video details, cover image, and internal chapters into the file)*[10].


6. Authentication & Cookies

  • Use cookies directly from your web browser:
yt-dlp --cookies-from-browser chrome "URL"

*(Extracts session cookies from Chrome, Firefox, Edge, Safari, Brave, etc. for private/age-restricted content)*[20].

  • Use an exported cookie file:
yt-dlp --cookies cookies.txt "URL"

*(Uses a Netscape-formatted cookie file for authentication)*[23][24].


7. Speed Optimization, Network & Proxies

yt-dlp -N 4 "URL"

*(Downloads 4 fragments concurrently for DASH/HLS streams)*[25].

yt-dlp --limit-rate 2M "URL"

*(Caps download bandwidth to 2 MB/s)*[25][28].

  • Download via HTTP or SOCKS5 Proxy:
yt-dlp --proxy "http://user:pass@proxy-server:port" "URL"

*(Routes traffic through a proxy to bypass geo-restrictions)*[3].


8. Trimming & Chapter Splitting

  • Split video into individual chapter files:
yt-dlp --split-chapters -o "%(title)s - %(chapter)s.%(ext)s" "URL"

*(Splits a video into separate files according to its internal chapters)*[31][32].

  • Download a specific time range:
yt-dlp --download-sections "*00:01:00-00:05:00" "URL"

*(Extracts and downloads only the section from 1:00 to 5:00)*[25][27].


9. Updates & Maintenance

  • Update executable binary:
yt-dlp -U

*(Updates standalone binaries to the latest release)*[3].

python3 -m pip install -U yt-dlp

(Updates yt-dlp *installed via pip)*[3][34].

  • Switch to the Nightly update channel:
yt-dlp --update-to nightly

*(Upgrades to the nightly channel for rapid bug fixes)*[35][36].


💡 Next Step: Would you like instructions on how to create a permanent yt-dlp.conf configuration file so you don't have to retype these flags every time?

Tuesday, 29 September 2026

How to Use yt-dlp Like Pro? - Comprehensive yt-dlp Guide & Reference Cheat Sheet



Comprehensive yt-dlp Guide & Reference Cheat Sheet

1. Prerequisites, Installation & System Integration

1.1 Platform-Specific Installation

yt-dlp is a cross-platform command-line media downloader. Depending on your operating system, it can be installed via standalone binary downloads, Python’s package manager (pip), or standard platform package managers.

Windows Installation

You can install yt-dlp using the Windows Package Manager (winget) or by downloading the standalone executable manually.

:: Installation via winget
winget install yt-dlp.yt-dlp

For manual installation:

  1. Create a directory such as C:\yt-dlp.
  2. Download yt-dlp.exe (64-bit standalone binary) from the official GitHub release page and place it into C:\yt-dlp.
  3. Add C:\yt-dlp to your System PATH environment variable via System Properties > Environment Variables.

macOS Installation

On macOS, install yt-dlp using Homebrew:

brew install yt-dlp

Linux Installation

You can download the platform-independent executable or the glibc-bundled standalone binary:

# Option A: Download the platform-independent zipimport executable
sudo curl -L https://github.com/yt-dlp/yt-dlp/releases/latest/download/yt-dlp
/-o /usr/local/bin/yt-dlp
sudo chmod a+rx /usr/local/bin/yt-dlp

# Option B: Download the standalone Linux x86_64 binary (bundled Python runtime)
sudo curl -L https://github.com/yt-dlp/yt-dlp/releases/latest/download/yt-dlp_linux
-o /usr/local/bin/yt-dlp
sudo chmod a+rx /usr/local/bin/yt-dlp

Alternatively, install or update yt-dlp in your Python environment via pip:

python3 -m pip install -U yt-dlp

Note on Binary Types & Package Managers: The primary yt-dlp release file (without an extension) is a platform-independent zipimport binary that requires Python 3.10+ pre-installed on the host system. If your environment lacks Python 3.10+, download the standalone binary (yt-dlp_linux for glibc x86_64 or yt-dlp_musllinux for Alpine/musl systems), which includes an embedded Python runtime via PyInstaller.

System package managers (such as Linux apt) often host outdated builds. Because streaming platforms frequently alter their video serving logic, outdated packages quickly suffer from extractor errors. Direct official binary downloads or pip installations are strongly recommended.

 

1.2 Installing and Integrating FFmpeg

FFmpeg is an essential dependency for yt-dlp. Modern media platforms host high-definition video and audio as separate adaptive streams. FFmpeg is required to merge these streams into a single container without re-encoding, perform format conversions, embed subtitles, and slice video segments.

System Installation Commands

  • Windows:
winget install Gyan.FFmpeg

(Alternatively, extract ffmpeg.exe from the Gyan.dev git full build ZIP directly into your yt-dlp directory).

  • macOS:
brew install ffmpeg
  • Linux (Debian/Ubuntu):
sudo apt install ffmpeg

Official FFmpeg Builds: For headless server environments or custom Linux setups, the project maintains official, optimized FFmpeg builds at yt-dlp/FFmpeg-Builds on GitHub, which offer maximum compatibility with yt-dlp post-processing operations.

 

Manual Path Override

If FFmpeg is installed outside your system PATH, specify its binary directory directly:

yt-dlp --ffmpeg-location /path/to/ffmpeg "URL"

1.3 Post-Installation Verification & Maintenance

Verify that both yt-dlp and ffmpeg are available in your shell environment:

yt-dlp --version
ffmpeg -version
yt-dlp -F "https://www.youtube.com/watch?v=BaW_jenozKc"
 

Update Maintenance Matrix

Installation Method

Update Command

Standalone Binary

yt-dlp -U

Python Pip

python3 -m pip install -U yt-dlp

Homebrew (macOS)

brew upgrade yt-dlp

Winget (Windows)

winget upgrade yt-dlp.yt-dlp 

 

 Switching Release Channels

yt-dlp offers three release channels: stable (monthly tagged releases), nightly (daily builds recommended for rapid extractor fixes), and master (canary builds compiled from every main branch commit).

# Switch binary to the recommended nightly development channel
yt-dlp --update-to nightly

# Switch binary to the master branch channel
yt-dlp --update-to master

# Pin or downgrade binary to a specific version tag
yt-dlp --update-to stable@2023.07.06

 

2. Fundamental Downloading & Format Inspection

2.1 Basic Video Downloading

To execute a default download, pass the target video URL enclosed in double quotes.

yt-dlp "https://www.youtube.com/watch?v=YE7VzlLtp-4"

 

Internal Download Execution Workflow

When executed, yt-dlp runs through the following sequence:

  1. Connects to the host site and extracts available video and audio metadata.
  2. Analyzes available streams and filters candidate stream identifiers.
  3. Selects the optimal video-only stream and audio-only stream based on quality rules.
  4. Downloads both selected streams concurrently into temporary partial files.
  5. Invokes FFmpeg to multiplex (mux) the video and audio streams into a unified container file (e.g., .mp4 or .mkv).
  6. Cleans up intermediate temporary stream files from the working directory.

 

2.2 Listing and Analyzing Formats (-F)

Inspect available video and audio streams without downloading the actual media using the -F (or --list-formats) flag.

yt-dlp -F "https://www.youtube.com/watch?v=YE7VzlLtp-4"

Representative Output Format Table

ID  EXT   RESOLUTION FPS │   FILESIZE   TBR PROTO │ VCODEC          VBR ACODEC      ABR
─────────────────────────────────────────────────────────────────────────────────────────
sb0 mhtml 48x27        1 │                  mhtml │ images                              
139 m4a   audio only      │    1.58MiB   49k https │ audio only          mp4a.40.5   49k
140 m4a   audio only      │    4.19MiB  130k https │ audio only          mp4a.40.2  130k
137 mp4   1920x1080   30 │   43.11MiB 1344k https │ avc1.640028   1344k video only
248 webm  1920x1080   30 │   28.08MiB  875k https │ vp9            875k video only
18  mp4   640x360     30 │  ~12.50MiB  500k https │ avc1.42001E         mp4a.40.2

 

Field Description Breakdown

  • ID: Extractor format code used for manual selection via -f.
  • EXT: Standard container format (e.g., mp4, webm, m4a).
  • RESOLUTION / FPS: Spatial dimensions and frame rate (audio only indicates missing video track).
  • FILESIZE / TBR: Total file size and Total Bitrate (kbps).
  • VCODEC / VBR: Video codec (e.g., avc1, vp9) and bitrate. video only indicates missing audio track.
  • ACODEC / ABR: Audio codec (e.g., mp4a.40.2, opus) and bitrate. audio only indicates pure audio track.

 

2.3 Manual Format Selection by Code (-f)

Select specific format IDs from the -F output table to override automatic stream selection.

# Download a single combined pre-merged format (ID 22)
yt-dlp -f 22 "URL"

# Merge specific video stream ID 137 with audio stream ID 140
yt-dlp -f 137+140 "URL"

# Fallback chain: attempt format 22, fallback to 17, then fallback to 18
yt-dlp -f 22/17/18 "URL"

 

3. Quality Control & Advanced Format Selection

3.1 Default Selection Rules & Fallbacks

yt-dlp evaluates stream priority differently than older downloaders such as youtube-dl.

Default Format Selector: bv*+ba/b By default, yt-dlp selects the best video stream (bv*) plus the best audio stream (ba). If a combined pre-merged video/audio stream (/b) provides superior quality to separate video and audio options, it downloads that combined stream instead.

  • Multistream Behavior: Enabling --audio-multistreams shifts default selection to -f bestvideo+bestaudio/best.
  • Stdout Streaming: Directing output to stdout (-o -) defaults to -f best/bestvideo+bestaudio if FFmpeg is unavailable.

 

3.2 Quality Capping and Resolution Limits

Constrain output quality and file extensions using bracketed stream conditions.

# Cap maximum resolution at 1080p
yt-dlp -f "bv*[height<=1080]+ba/b[height<=1080]" "URL"

# Force strict MP4/M4A input containers with explicit MP4 output muxing
yt-dlp -f "bv*[ext=mp4]+ba[ext=m4a]/b[ext=mp4]" --merge-output-format mp4 "URL"

# Grouped selection syntax: filter pre-merged mp4 or webm streams under 480p
yt-dlp -f "(mp4,webm)[height<480]" "URL"

 

3.3 Format Sorting Strategies (-S / --format-sort)

The -S flag alters stream selection priority without requiring complex -f conditional syntax. By default, format fields are evaluated in descending order, and multiple sort criteria can be chained using a comma-separated string (e.g., -S "res:720,vcodec:h264,fps").

Format Sort Fields and Modifiers Matrix

Sort Field

Description

Example Usage

res / height

Resolution (evaluated by smallest dimension for vertical video support).

-S "res:720" (Cap at 720p)

fps

Frame rate.

-S "res:720,fps"

size / filesize

Exact or estimated file size.

-S "+size" (Smallest file size)

br / vbr / abr

Bitrate (total, video, or audio).

-S "+size,+br"

vcodec

Video codec (av01 > vp9.2 > vp9 > h265 > h264 > vp8).

-S "codec:h264"

acodec

Audio codec (flac/alac > opus > vorbis > aac > mp3).

-S "acodec:aac"

ext

Extension preference (mp4 > mov > webm > flv).

-S "ext"

proto

Transfer protocol (https > http > m3u8_native).

-S "proto"

Modifier Syntax Rules

  • + (Prefix): Reverses sorting order to ascending (e.g., +size selects smallest file).
  • : (Suffix): Sets a hard preference threshold (e.g., res:1080).
  • ~ (Suffix): Prefers the value closest to the target parameter (e.g., filesize~50M).

 

3.4 Advanced Format Filtering Parameters

Filters inside square brackets [KEY OPERATOR VALUE] inspect stream metadata attributes.

  • Numeric Fields: filesize, filesize_approx, width, height, tbr, abr, vbr, fps, asr, audio_channels.
  • String Fields: ext, acodec, vcodec, container, protocol, language, format_id.
  • Available Operators: <, <=, >, >=, =, !=, ^= (starts with), $= (ends with), *= (contains), ~= (regex match), ! (negation).
# Select up to 720p video (or missing height field) with total bitrate > 500 kbps
yt-dlp -f "bv[height<=?720][tbr>500]+ba" "URL"

# Extract all audio-only streams matching filter
yt-dlp -f "all[vcodec=none]" "URL"

 

4. Audio Extraction & Media Processing

4.1 Standard Audio Extraction (-x)

The -x (or --extract-audio) option instructs yt-dlp to discard the video track and extract the standalone audio stream.

yt-dlp -x "https://www.youtube.com/watch?v=YE7VzlLtp-4"

Stream Copying vs. Re-encoding: By default, -x extracts the source audio format directly (e.g., .opus or .m4a) without re-encoding. This process completes quickly with zero generational quality loss.

 

4.2 Audio Format Conversion & Quality Flags

To force conversion of the extracted audio stream into a specific format, combine -x with --audio-format and --audio-quality.

  • Supported --audio-format Targets: best (default), aac, alac, flac, m4a, mp3, opus, vorbis, wav.
  • Quality Settings (--audio-quality): Accepts values from 0 (highest VBR quality) to 10 (lowest VBR quality), or explicit bitrates like 128K or 320K (default is 5).
# Convert audio stream to MP3 at variable bitrate quality 0
yt-dlp -x --audio-format mp3 --audio-quality 0 "URL"

# Extract and wrap audio stream in lossless FLAC container
yt-dlp -x --audio-format flac "URL"

Lossy-to-Lossy Quality Warning: Converting compressed web audio (such as YouTube Opus or AAC) into MP3 forces a secondary lossy encoding pass, causing minor audio degradation. To retain maximum fidelity, use --audio-format best or keep native M4A/Opus containers unless target playback devices strictly require MP3. 

4.3 Cover Art, Metadata, and File Preservation Flags

# Tagged MP3 download pipeline with embedded artwork and video retention
yt-dlp -x \
  --audio-format mp3 \
  --audio-quality 0 \
  --embed-thumbnail \
  --embed-metadata \
  -k "URL"
  • -k (--keep-video): Retains the original intermediate video file on disk alongside the converted audio output.
  • --embed-thumbnail: Embeds cover art directly into audio tags (requires mutagen or AtomicParsley).
  • --embed-metadata: Writes title, artist, uploader, and date metadata into the output file.

 

5. Playlist, Channel, and Batch Downloads with Archive Logging

5.1 Playlist Range Control and Slicing

Filter and select specific items within remote playlists using range limits or Python slice syntax.

# Download playlist items 1 through 5
yt-dlp --playlist-start 1 --playlist-end 5 "PLAYLIST_URL"

# Index slicing syntax (-I or --playlist-items): items 1
# to 3, item 7, and every second item from item 11 onward
yt-dlp -I 1:3,7,11::2 "PLAYLIST_URL"

# Download every second video in a playlist
yt-dlp -I 1::2 "PLAYLIST_URL"

# Process playlist entries in reverse order
yt-dlp --playlist-reverse "PLAYLIST_URL"

# Process playlist entries in randomized order
yt-dlp --playlist-random "PLAYLIST_URL"

5.2 Channel Ingestion and Batch File Processing (-a)

Process complete channel feeds or read target URLs from a batch text file using -a or --batch-file.

# Sample batch file: urls.txt
# Lines starting with '#', ';', or ']' are treated as comments

https://www.youtube.com/watch?v=YE7VzlLtp-4
https://www.youtube.com/watch?v=ptd1NN40vMw
# Comment line: skip unreachable URL
;https://www.youtube.com/watch?v=invalid_id
https://www.youtube.com/@TheLinuxFoundation

Execute batch downloads with:

yt-dlp -a urls.txt

5.3 Preventing Duplicate Downloads (--download-archive)

For continuous backup automation or channel archiving, use --download-archive to record processed video IDs.

yt-dlp --download-archive archive.txt --break-on-existing "https://www.youtube.com/@ChannelName"

Operational Breakdown

  • archive.txt Mechanics: yt-dlp logs extracted video IDs to this text file upon successful download. Subsequent executions match extracted IDs against archive.txt and skip previously downloaded videos.
  • --break-on-existing: Terminates playlist processing as soon as an archived ID is encountered, reducing redundant API requests when scanning updated channels.

 

6. Output Template Formatting (-o) & Path Control (-P)

6.1 Output Template Syntax & Variables

The -o flag controls filename patterns using Python string formatting: %(name[.keys][addition][>strf][,alternate][&replacement][|default])type

Core Metadata Template Keys

Template Key

Description

Sample Output Value

%(title)s

Sanitized video title.

Installing yt-dlp

%(id)s

Unique extractor ID.

YE7VzlLtp-4

%(ext)s

Output container extension.

mp4

%(upload_date)s

UTC upload date (YYYYMMDD).

20250115

%(upload_date>%Y-%m-%d)s

Custom strftime formatted date.

2025-01-15

%(uploader)s

Uploader/channel display name.

LinuxFoundation

%(playlist)s

Parent playlist name.

Linux Tutorials

%(playlist_index)s

Index position in playlist.

01

%(resolution)s

Spatial resolution.

1920x1080

%(duration_string)s

Media duration formatted as HH:MM:SS.

00:12:34

Filename Sanitization Flags

  • --restrict-filenames: Restricts output filenames strictly to ASCII characters, eliminating spaces and ampersands.
  • --windows-filenames: Forces filenames to comply with Windows filesystem naming rules.

6.2 Structuring Directory Trees

Output templates accept directory path separators to organize downloads based on extracted metadata:

# Save playlist items into a directory named after the playlist
yt-dlp -o "%(playlist)s/%(playlist_index)s - %(title)s.%(ext)s" "PLAYLIST_URL"

# Group downloads by Uploader and Upload Year
yt-dlp -o "%(uploader)s/%(upload_date>%Y)s/%(title)s.%(ext)s" "URL"

# Organize episodic shows into Series/Season/Episode structures
yt-dlp -o "%(series)s/%(season_number)s - %(season)s/%(episode_number)s - %(episode)s.%(ext)s" "URL"

6.3 Advanced Path Assignment (-P / --paths)

The -P flag sets output and temporary download directories separately from filename templates.

# Set final output path, separate temp path, and subtitle target location
yt-dlp -P "C:/MyVideos" -P "temp:tmp" -P "subtitle:subs"
-o "%(uploader)s/%(title)s.%(ext)s" --write-subs "URL"

 

7. Subtitles, Metadata, Cover Art, and SponsorBlock Integration

7.1 Subtitle Extraction and Embedding

# List available subtitle languages and formats
yt-dlp --list-subs "URL"

# Subtitle retrieval and container embedding pipeline
yt-dlp \
  --write-subs \
  --write-auto-subs \
  --sub-langs "en.*,ja" \
  --convert-subs srt \
  --embed-subs "URL"
  • --write-subs / --write-auto-subs: Downloads manual or automatically generated captions.
  • --sub-langs: Accepts language tags or regex matching patterns (e.g., "en.*,ja" matches all English regional variants and Japanese).
  • --convert-subs: Converts downloaded captions into srt, vtt, ass, or lrc formats.
  • --embed-subs: Embeds subtitles directly into .mp4, .webm, or .mkv containers.

7.2 Metadata Tagging & In-Flight Modifications

# Embed primary metadata tags into media container
yt-dlp --embed-metadata "URL"

# Parse metadata field: interpret Title as "Artist - Title"
yt-dlp --parse-metadata "title:%(artist)s - %(title)s" "URL"

# Replace spaces and underscores in title and uploader fields with hyphens
yt-dlp --replace-in-metadata "title,uploader" "[ _]" "-" "URL"

7.3 Thumbnail Operations

# Download thumbnail, convert to JPG, and embed as cover art in an MP3 file
yt-dlp -x --audio-format mp3 --write-thumbnail --convert-thumbnails jpg --embed-thumbnail "URL"

7.4 SponsorBlock Integration

yt-dlp integrates with the SponsorBlock API to mark or cut sponsored segments, intros, and filler content during download.

Category Restrictions & Rules

  • Available Categories: sponsor, intro, outro, selfpromo, preview, filler, interaction, music_offtopic, hook, poi_highlight, chapter, all, default.
  • Marking vs. Removing: The poi_highlight and chapter categories are supported only for --sponsorblock-mark and cannot be passed to --sponsorblock-remove.
  • Default Target Resolution: Passing default to --sponsorblock-remove evaluates to all,-filler.
# Create internal chapters for sponsor segments while skipping preview markers
yt-dlp --sponsorblock-mark all,-preview "URL"

# Cut sponsor and intro segments out of the media file (requires FFmpeg)
yt-dlp --sponsorblock-remove "sponsor,intro" "URL"

 

8. Authentication Mechanisms

8.1 Browser Cookie Extraction (--cookies-from-browser)

Extract session cookies directly from installed web browsers to download private, age-restricted, or member-only content.

Supported Browsers

brave, chrome, chromium, edge, firefox, opera, safari, vivaldi, whale.

Command Syntax

--cookies-from-browser BROWSER[+KEYRING][:PROFILE][::CONTAINER]

  • Keyring Identifiers: basictext, gnomekeyring, kwallet, kwallet5, kwallet6.
  • Firefox Container: The CONTAINER suffix applies exclusively to Firefox profiles (or none to disable container checking).
# Extract cookies from default Chrome browser installation
yt-dlp --cookies-from-browser chrome "URL"

# Extract cookies from Firefox profile using a specific keyring
yt-dlp --cookies-from-browser firefox+gnomekeyring "URL"

Linux Keyring Security Note: On Linux systems decrypting Chromium-based browser cookies, yt-dlp requires the Python secretstorage package to access system keyrings (gnomekeyring or kwallet).

8.2 File-Based Cookie Usage (--cookies)

For headless server setups or unsupported browser environments, export cookies to a Netscape-formatted file:

yt-dlp --cookies cookies.txt "URL"

8.3 .netrc and Credential Management

Store login credentials in a .netrc file for automated authentication without passing plaintext passwords on the command line.

Step 1: Create .netrc File & Set Permissions

Create ~/.netrc and restrict read/write access to the local user:

touch ${HOME}/.netrc
chmod a-rwx,u+rw ${HOME}/.netrc

Step 2: Configure Credential Entries

Add service account credentials using the lowercase extractor identifier:

machine youtube login myaccount@gmail.com password mypassword123
machine twitch login my_twitch_user password my_twitch_password

Step 3: Invoke Authentication

Activate .netrc lookup via --netrc or pass dynamic decryption commands using --netrc-cmd:

# Enable standard netrc credential lookup
yt-dlp --netrc "URL"

# Decrypt GPG-encrypted authinfo file on demand
yt-dlp --netrc-cmd 'gpg --decrypt ~/.authinfo.gpg' "URL"

 

9. Persistent Configuration Setup (yt-dlp.conf)

9.1 Configuration File Locations & Priority Order

Configuration options are evaluated on every yt-dlp run in the following priority order:

  1. Explicit Location: Paths supplied via --config-locations PATH.
  2. Portable Configuration: yt-dlp.conf in the executable binary directory.
  3. Home Configuration: yt-dlp.conf inside the path supplied to -P, or the current directory.
  4. User Configuration:
    • Linux / macOS: ${XDG_CONFIG_HOME}/yt-dlp/config (typically ~/.config/yt-dlp/config).
    • Windows: %APPDATA%/yt-dlp/config (typically C:\Users\<User>\AppData\Roaming\yt-dlp\config).
  5. System Configuration: /etc/yt-dlp.conf.

(To bypass configuration files for a specific execution, pass --ignore-config).

9.2 Syntax & Formatting Rules

  • Place one command option per line.
  • Do not leave leading whitespace before option switches.
  • Lines beginning with # are treated as comments.
  • File encoding can be declared on the first line via # coding: utf-8.

Configuration Do's and Don'ts

# ==========================================
# VALID CONFIGURATION FILE
# ==========================================
# coding: utf-8
-o ~/Downloads/%(title)s.%(ext)s
--embed-metadata
--format-sort res:1080

# ==========================================
# INVALID CONFIGURATION FILE (DO NOT USE)
# ==========================================
 -o ~/Downloads/%(title)s.%(ext)s     # ERROR: Leading whitespace before flag
--proxy 127.0.0.1:1080                # WARNING: Unquoted strings containing spaces

9.3 Production Configuration Template

Save the following configuration as your user profile (e.g., ~/.config/yt-dlp/config) for standard archival downloading:

# coding: utf-8
# Production Configuration Template for yt-dlp

# Default output directory and filename template
-o ~/Downloads/%(uploader)s/%(upload_date>%Y-%m-%d)s - %(title)s [%(id)s].%(ext)s

# Prefer 1080p MP4/M4A streams with fallback to general formats
-f bv*[height<=1080][ext=mp4]+ba[ext=m4a]/b[height<=1080][ext=mp4]/bv*+ba/b
--merge-output-format mp4

# Embed metadata, thumbnails, and subtitles
--embed-metadata
--embed-thumbnail
--embed-subs
--sub-langs "en.*"

# Archive file location to skip duplicates
--download-archive ~/.config/yt-dlp/download_archive.txt

# Download speed and fragment optimization
--concurrent-fragments 4

 

10. Advanced Execution & Network Tuning

10.1 Section Trimming and Chapter Splitting

Slice specific time intervals or split videos into independent files based on embedded chapter markers.

# Download a precise timestamp section (1 minute to 5 minutes)
yt-dlp --download-sections "*00:01:00-00:05:00" "URL"

# Split video into separate files using chapter boundaries
yt-dlp --split-chapters -o "%(title)s - %(chapter_number)s %(chapter)s.%(ext)s" "URL"

# Omit chapters matching regex pattern from the download
yt-dlp --remove-chapters "sponsor" "URL"

10.2 Network Proxies and Client Impersonation

Bypass geo-restrictions, IP rate limits, and TLS fingerprinting using proxy routing and browser impersonation.

# Route traffic through an HTTP/HTTPS proxy
yt-dlp --proxy "http://username:password@proxy.example.com:8080" "URL"

# Route traffic through a SOCKS5 proxy
yt-dlp --proxy "socks5://127.0.0.1:1080" "URL"

# Impersonate browser TLS fingerprints using curl_cffi
yt-dlp --impersonate "chrome" "URL"

# Inject X-Forwarded-For headers to spoof client origin country
yt-dlp --xff "US" "URL"

Impersonation Dependency Note: The curl_cffi package is pre-bundled in most official release binaries except the Unix zipimport binary (yt-dlp) and 32-bit Windows binary (yt-dlp_x86.exe). If you are running the Unix zipimport binary, install curl_cffi via pip install "yt-dlp[default,curl-cffi]" to enable --impersonate.

10.3 Speed Optimization & Rate Limiting

Tune connection parallelism or limit bandwidth consumption.

# Download 8 DASH/HLS stream fragments concurrently
yt-dlp -N 8 "URL"

# Limit download rate to 2 Megabytes per second
yt-dlp -r 2M "URL"

# Set minimum bitrate threshold to trigger re-extraction if connection is throttled
yt-dlp --throttled-rate 100K "URL"

# Set request sleep intervals to avoid IP rate-limiting blocks
yt-dlp --sleep-requests 0.75 --sleep-interval 5 --max-sleep-interval 20 "URL"

 

11. Scenario-Based Command Cheat Sheet

11.1 Rapid Reference Table

Scenario / Goal

Complete Command Line

1. Highest Quality Default

yt-dlp "URL"

2. Max 1080p MP4 + Subs + Metadata

yt-dlp -f "bv*[height<=1080][ext=mp4]+ba[ext=m4a]/b[height<=1080]" --merge-output-format mp4 --embed-subs --embed-metadata "URL"

3. High Quality MP3 + Art + Tags

yt-dlp -x --audio-format mp3 --audio-quality 0 --embed-thumbnail --embed-metadata "URL"

4. Full Channel Backup (Archive Skip)

yt-dlp --download-archive archive.txt --break-on-existing -o "%(uploader)s/%(title)s.%(ext)s" "https://www.youtube.com/@Channel"

5. Playlist Subset in Reverse

yt-dlp -I 1:10 --playlist-reverse "PLAYLIST_URL"

6. Trim Precise Timestamp Segment

yt-dlp --download-sections "*00:01:30-00:03:45" "URL"

7. Private Video (Chrome Cookies)

yt-dlp --cookies-from-browser chrome "URL"

8. SOCKS5 Proxy + Sponsor Block Cut

yt-dlp --proxy "socks5://127.0.0.1:1080" --sponsorblock-remove "sponsor,intro" "URL"

9. Audio Batch List + Rate Limit

yt-dlp -a urls.txt -x --audio-format mp3 --limit-rate 2M -N 4

10. Chapter Splitting into Subdirectories

yt-dlp --split-chapters -o "%(title)s/Chapter %(chapter_number)s - %(chapter)s.%(ext)s" "URL"

Sunday, 27 September 2026

AI Credential Theft and LLMjacking: How UK SMEs Can Protect Their AI Accounts in 2026


Published by GLCTech Sec, the UK monitoring, endpoint security and backup partner for regulated SMEs.

AI credential theft is one of the fastest-growing cyber threats of 2026. New research from Google, Okta, and Anthropic shows criminals are going after more than just your data. They are stealing API keys, login sessions, and cloud accounts behind the AI tools your business uses, then running up bills, reselling access, or using it for extortion. This guide explains what is happening, why UK accountancy, legal and financial firms should pay attention, and the practical steps that reduce the risk.

What is AI credential theft?

AI credential theft is the theft of anything that grants access to an AI service or the cloud infrastructure behind it. That includes:

  • API keys used by software to call AI services;
  • Session tokens, the browser cookies that keep you logged in to AI assistants and cloud portals;
  • Cloud account credentials that can be used to switch on and consume AI services.

Google Threat Intelligence Group's AI Threat Tracker (8 September 2026) reports attackers stealing API credentials, targeting proprietary AI models and source code, and taking over victims' cloud environments to run unauthorised AI workloads.

What is LLMjacking?

LLMjacking is the term security researchers at Sysdig coined in 2024 for hijacking someone else's large language model (LLM) access. The attacker uses stolen credentials to run AI workloads, and the victim pays. In its original research, Sysdig estimated one attack could generate more than US$46,000 of AI usage costs per day.

The problem has grown since. Okta Threat Intelligence's September 2026 research describes one organisation facing a bill of nearly US$1 million, an individual software architect hit with a US$25,000 surprise bill, and an AI testing organisation losing US$600,000 in AI credits because of a stolen API key.

How are AI accounts being stolen?

1. Infostealer malware on staff devices

Infostealers are malware that quietly harvest saved passwords and browser session tokens from infected computers. Okta analysed a large dump of infostealer logs and found thousands of AI-platform session tokens. With a valid token, an attacker can replay your session and bypass both the password and multi-factor authentication.

2. Keys left in code, containers and shared files

Anthropic's September 2026 threat report describes attackers systematically searching public code repositories, container images, apps and websites for credentials and API keys. In one case, a single stolen developer token escalated to full administrative control of a victim's cloud environment in roughly three hours.

3. Buying access on underground markets

According to reporting on Google's findings, underground prices for stolen AI accounts, particularly Claude and Gemini accounts, more than doubled during 2026. Rising prices signal rising demand.

From stolen access to extortion

Stolen AI data is also being used for ransom. Google's Mandiant investigated several extortion cases in Q2 2026 in which attackers stole proprietary AI models, prompts, source code and research from technology, healthcare and media companies in North America and Europe, then threatened to publish the data unless the victim paid.

Regulators are now seeing AI-executed incidents too. In September 2026, Spain's data protection authority (AEPD) reported receiving its first breach notification in which the victim organisation said an AI agent logged in and autonomously found a flaw that let it modify personal data and access invoices. The AEPD stressed that the account comes from the victim's notification and is still under analysis.

Why UK accountancy, legal and financial firms should care

Most professional-services SMEs are not building their own AI models. Your realistic exposure is more everyday:

  • a staff laptop infected with an infostealer, leaking sessions for email, cloud and AI tools;
  • an API key for an AI-enabled product pasted into a script, spreadsheet or shared drive;
  • an unnoticed spike in cloud or AI usage that only shows up on the invoice;
  • client personal data processed through AI tools becoming reachable by an attacker.

If personal data is involved, UK GDPR still applies in full. Notifiable breaches must be reported to the ICO within 72 hours (see the ICO's breach reporting page). For firms that answer to clients, insurers and regulators, "it was an AI" is not a defence.

7 steps to protect your business from AI credential theft

  1. Harden every endpoint. Use managed endpoint protection that is actively monitored, because infostealers start on user devices.
  2. Remove secrets from code and files. Scan repositories and containers for exposed keys, and use a secrets manager instead of hard-coding credentials.
  3. Rotate exposed keys immediately. Treat any key that has appeared in a repo, ticket, email or chat as compromised.
  4. Set spending limits and billing alerts on every cloud and AI account, so a hijacked key triggers an alert rather than an invoice shock.
  5. Monitor for anomalies 24/7. Unusual traffic, logins and resource usage across servers, networks and applications are often the first sign of compromise.
  6. Keep immutable, tested backups. A reliable restore turns an extortion demand into a manageable incident.
  7. Govern your AI use. Know which AI tools staff use, what data goes into them and who holds the keys. Treat prompts and AI configurations as sensitive assets.

The NCSC's free guidance for small and medium-sized organisations is a strong baseline for all of the above.

How GLCTech Sec helps you stay ahead

GLCTech Sec helps UK regulated SMEs put these controls in place without building an in-house security team:

We publish our own security posture openly on our Trust & Compliance page, including UK GDPR processing terms and our progress towards Cyber Essentials certification.

Book a free 30-minute Security Gap Assessment at glctechsec.com, or email contact@glctechsec.com.

Frequently asked questions

Can attackers get into my AI account without my password?

Yes. If malware steals a valid session token from your browser, an attacker can replay it and access the account without the password or MFA code. Okta's September 2026 research documents this happening at scale.

Who pays when a stolen API key is used?

Usually the account owner. Usage is billed to the account the key belongs to, which is why spending limits and billing alerts matter.

We don't build AI. Are we still at risk?

Yes. If your staff use AI assistants, AI-enabled software or cloud services, their sessions and keys are worth stealing. The most common route in is an infected endpoint, not a sophisticated attack on an AI model.

What is the quickest first step?

Find out where you stand. A short gap assessment covering endpoints, monitoring, backups and exposed credentials will show your biggest risks. GLCTech Sec offers one free.

Sources

Demystifying Password Manager Cryptography and Vault Recovery: An IT Learner’s Guide

  1. Introduction to Digital Vault Security Modern password managers rely on a foundational security framework known as Zero-Knowledge Archi...