How I Lost ₹2.78 Lakh on Freepik Magnific: The AI API Loophole Every Creator Must Know | Editzaar

How I Lost ₹2.78 Lakh on Freepik Magnific: The AI API Loophole Every Creator Must Know | Editzaar

"I have been a paying customer on Freepik and Magnific AI for over two years without a single issue. Then, in the span of forty-eight hours, five separate transaction alerts drained ₹2,78,196 from my bank account. Here is the exact story of how it happened, the security flaw behind it, and what every studio must do right now."

The Notification That Shook My Morning

It started like any other routine workday. An email pinged in my inbox with a casual subject line: 'Your File is Ready to Download.'

I clicked the notification expecting to see an asset from our ongoing client projects. Instead, my dashboard showed high-resolution renders being generated for a production titled 'Nigerian Webseries'. A project I never created. A team I never hired. Prompts I had never typed in my life.

I opened my banking app. My stomach dropped.

There were five unauthorized debits sitting in my billing statements between September 28 and September 30, 2026. One charge of ₹2,076.80, followed by four brutal, back-to-back charges of ₹69,030 each. In less than forty-eight hours, exactly ₹2,78,196.80 had been siphoned through my saved billing credentials.

Verified Billing Evidence (Magnific Invoice Records)
Magnific AI Invoice Proof showing 4x 69030 INR and 2076 INR charges
Invoices from user subscription dashboard showing four separate charges of ₹69,030 and one of ₹2,076.80 within 48 hours.

How the Exploit Worked: The API Credit Trap

When I inspected the account settings, the anatomy of the breach became crystal clear:

  1. Account Compromise: An unauthorized third party gained access to my Magnific account session.
  2. Rogue API Key Generation: Without requiring two-factor confirmation (2FA) or email re-authentication, the intruder created multiple active API keys under my profile.
  3. Automated 1-Million Credit Purchases: The attacker wrote a script that repeatedly bought 'Magnific Extra Credits 1M - Premium+ Annual' packs at ₹69,030 per pop, charging my saved card automatically without triggering a single One-Time Password (OTP) prompt.
  4. Asset Harvesting: The attacker used those millions of stolen credits to mass-generate AI-upscaled video and image assets for their external production, leaving me with the financial wreckage.

The Silence from Customer Support

Being a loyal customer for two years counts for nothing when platform security fails. I submitted emergency tickets through official support channels explaining the unauthorized breach and attaching bank transaction references.

Days have passed. Zero response. No acknowledgment. No temporary freeze on the compromised account.

Further research across creator forums revealed a troubling reality: I am not the only one. Multiple creators and design agencies have reported similar instances where saved card details on Magnific were drained through rapid API credit purchases without basic fraud detection kicking in.

The 3 Critical Security Failures Freepik Magnific Must Fix

Software platforms processing enterprise payments have a fundamental duty of care. Magnific and Freepik failed on three elementary security standards:

1. Zero Spending Velocity Limits

Any basic payment gateway should immediately flag an account that suddenly charges ₹2.76 Lakh within twenty-four hours after months of baseline usage. Magnific processed four identical ₹69,030 transactions back-to-back without batting an eye.

2. Lack of Step-Up 2FA for APIs

Creating an API key that has permission to trigger automated purchases should strictly require biometric verification, an authenticator app code, or SMS confirmation. It did not.

3. No Multi-Session Invalidation

When a login happens from a completely different geographic IP address, modern services alert the user or kill stale sessions. The attacker operated in parallel with my account undetected.

What Every Creator and Agency Must Do Today

If you use Freepik, Magnific, Midjourney, RunWay, or any generative platform with a credit card on file, protect yourself before this happens to your business:

  1. Never Leave Credit Cards Saved on AI Platforms: Remove your primary business debit or credit card from subscription dashboards. Use virtual single-use cards or prepaid cards with a strict spending ceiling (e.g. ₹5,000 maximum balance).
  2. Audit Your API Keys Right Now: Open your account settings under the API tab. If you see keys you did not personally generate, delete them immediately and rotate your account password.
  3. Set Up Daily Bank Limits: Log into your net banking app and set an explicit domestic and international transaction limit. Cap daily online transactions to an amount that won't ruin your business if breached.
  4. File Bank Disputes Within 72 Hours: If unauthorized debits hit your account, call your issuing bank immediately. Demand an official transaction dispute form and file a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in or helpline 1930 in India). Prompt reporting is legally vital for chargeback recovery.

A Direct Message to the Freepik & Magnific Team

This is not an isolated bug; it is an active vulnerability costing loyal creators hundreds of thousands of rupees. We urge Freepik and Magnific leadership to investigate these unauthorized transaction reference IDs, refund the stolen funds, and implement mandatory multi-factor authentication for API generation and credit auto-refills immediately.

Published by Editzaar Case Studies Series • Category: Cybersecurity & Creator Safety • India

Post a Comment

0 Comments