Introduction
The rapid democratization of generative AI has brought transformative power to millions of creators, but it has also opened lucrative new avenues for cyber-fraud. In a sophisticated campaign that highlights the vulnerabilities inherent in scaling high-cost AI infrastructure, bad actors have successfully gamed Canva’s AI credit system. By exploiting a structural weakness in account management, fraudsters transformed thousands of free trial accounts into “token mines,” effectively harvesting vast amounts of generative AI power to be sold on the black market at a steep discount.
This breach, which centers on the integration between the design giant Canva and the generative AI platform Leonardo.ai, underscores the growing tension between rapid product expansion and the necessity for robust fraud prevention. As businesses grapple with the rising costs of “AI sprawl,” this incident serves as a stark warning about the hidden fiscal risks of cloud-based generative tools.
The Mechanics of the Breach: "Seat Cycling"
The operation was not a brute-force hack in the traditional sense, but rather an exploitation of business logic. The fraudsters utilized a tactic known as “seat cycling,” which leveraged the administrative linkages between Canva and its 2024 acquisition, Leonardo.ai.
When Canva integrated Leonardo.ai—a platform it purchased for $320 million to bolster its generative capabilities—it introduced a generous incentive for business users. New Canva Business trial accounts were granted access to Leonardo.ai’s "Essential" tier. This tier provided users with 8,500 "fast tokens" per month, alongside a 25,500-token rollover bank, allowing users to generate high-fidelity images, textures, and assets.
Fraudsters discovered that by automating the creation of these trial accounts and repeatedly cycling them through the sign-up and integration process, they could aggregate tens of thousands of tokens into central accounts. These “token mines” were then leveraged to fulfill commercial requests from third-party buyers who were eager to bypass Canva’s standard subscription pricing.
Chronology of the Exploitation
The Integration Phase (2024)
Following the $320 million acquisition of Leonardo.ai, Canva’s leadership team—Melanie Perkins, Cliff Obrecht, and Cameron Adams—began the ambitious task of folding the startup’s technology into the Canva suite. The goal was to provide enterprise-grade generative AI to a broader user base. During the rollout, the system was configured to reward business trialists with an aggressive token allocation to encourage adoption and user retention.
The Discovery of the Loophole (Early 2025)
By early 2025, digital forensic analysts began noticing unusual activity on secondary market platforms. Bulk batches of AI generation credits, purportedly tied to professional-grade accounts, were being sold at 60% to 80% below the retail cost of a standard Canva or Leonardo subscription. The perpetrators had identified that the automated verification systems for the Business trial sign-ups lacked a sufficient "cool-down" or hardware-binding mechanism.
The Escalation (Mid-2025)
As the scheme matured, the fraudsters moved from manual account creation to sophisticated scripts. These scripts could bypass basic CAPTCHA protections and automate the integration of trial seats with Leonardo.ai. This led to a massive influx of "ghost accounts" that existed solely to accumulate and transfer token balances.
The Crackdown (Late 2025 – Present)
By late 2025, Canva’s internal monitoring systems flagged an anomalous spike in token consumption that did not correlate with actual creative output. Security teams, alerted by the discrepancy between the volume of token generation and the inactivity of the associated design projects, began a systematic audit of the trial user lifecycle.
Supporting Data: The Economics of the Black Market
The sheer scale of this operation is evidenced by the token volumes involved. A single "cycled" account could generate a combined 34,000 tokens (8,500 monthly + 25,500 rollover). When multiplied by the thousands of automated accounts, the fraudsters were effectively controlling millions of tokens per month.
For the end-user, the appeal was simple: businesses facing "AI fatigue" and ballooning cloud software budgets were looking for ways to cut costs. By purchasing discounted tokens from these black-market providers, companies could sustain their high-volume AI workflows without triggering the internal finance departments responsible for overseeing software subscriptions.
| Metric | Impact |
|---|---|
| Token Theft Scale | Estimated at >50 million tokens/month at peak |
| Market Discount | 60–80% below official retail pricing |
| Exploitation Vector | Automated Business Trial sign-ups |
| Primary Target | Leonardo.ai Essential tier integration |
Official Responses and Remediation
In a formal statement, a Canva spokesperson addressed the incident, acknowledging that while no user data was compromised, the integrity of the credit system had been temporarily undermined.
"We are committed to providing the world’s most accessible AI design tools. Unfortunately, bad actors sometimes exploit the very systems designed to offer value to our legitimate business users," the spokesperson said. "Upon identifying the ‘seat cycling’ behavior, our engineering teams implemented stricter verification protocols, including enhanced device fingerprinting and improved anti-bot measures during the trial onboarding process."
Canva has also introduced a "fair usage policy" for trial accounts, which limits the rate at which tokens can be claimed and prohibits the transfer of credits between accounts. The company is currently working with third-party marketplaces to remove listings associated with the illicit sale of these tokens.
Implications: The High Cost of Generative AI
The fallout from this incident extends far beyond the immediate financial loss for Canva. It represents a pivot point in how SaaS companies manage the "hidden cost" of AI.
1. The Death of Unlimited Trials
This incident likely marks the end of the era of "no-friction" AI trials. Companies are moving toward more stringent verification, such as requiring verified corporate email addresses (rather than disposable domains) or mandatory payment method pre-authorization, even for trials.
2. The Financialization of AI
AI tokens are increasingly becoming a form of "digital currency." As long as these tokens have tangible value—allowing for the generation of content that saves businesses thousands of dollars in design hours—they will remain a target for organized crime. The industry must move toward hardware-locked or user-identity-locked tokens to prevent mass-scale aggregation.
3. The "Uncontrolled Spending" Problem
The success of this fraud highlights a broader cultural issue in corporate environments: "AI Shadow IT." Because departments are under pressure to utilize AI tools but are often constrained by central IT budgets, employees are increasingly turning to unofficial, discounted, or "grey-market" sources to meet their quotas. This behavior exposes corporations to significant security risks, as they often have no visibility into the provenance of the AI services their employees are using.
4. The Future of AI Infrastructure Security
As AI models become more integrated into business workflows, the security of the API and credit-management layer must be treated with the same rigor as sensitive customer data. Fraud detection in the age of AI must move from reactive to predictive, utilizing machine learning models that can identify the "behavioral footprint" of an automated bot before it has the chance to exhaust a company’s resources.
Conclusion
The gaming of Canva’s AI credit system is a cautionary tale for the tech industry at large. It illustrates that as companies rush to integrate generative AI into their products, the potential for exploitation grows exponentially. While Canva has taken steps to plug the leak, the incident leaves a lasting impact on the ecosystem.
For the founders and the wider tech community, the challenge is clear: balance the user-friendly ethos of a creative platform with the iron-clad security required to protect the expensive, resource-intensive nature of modern generative AI. As businesses continue to integrate these tools into their daily operations, the focus must shift from rapid scaling to sustainable, secure, and transparent infrastructure. The era of "free-for-all" AI credits is over; the era of secure, verified, and audited AI resource management has begun.
