Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- In my project, I pay a general price for using agent quota. For me, it's not about saving money but about being sure that I have full control over the usage limits. My product provides a pool that depends on the plan (100 or 500 requests per paying account per month), and when these credits are used, I offer a backup option to bring your own AI key to use. And last but not least, I want to be sure that users' data won't be used to train models.by alekstret
- For anyone looking to cash out unused AI credits, I'd pay 30% for Azure, 40% for GCP, 50% for OpenAI, and 65% for AWS/Anthropic.by cdxy
- So are they stealing from their employers or is something else going on?by topbanana
- Stolen credit cards
Demo accounts
Free trials
Unlimited chat relays (eg chatgpt chat)
Leaked company credentials
Etc
by huflungdung - nope - a.i companies to promote their platforms offer 'a.i' credits to startups usually worth 10ks, 100ks worth of credits in $ terms.
so to a startup - you can trade your credits - then get actual cash.
just like you would if trading debt etc.
by dzonga - Most of these are your standard botnet rings. Either accounts directly are taken over, and the attacker adds 2FA or carding rings take stolen #s and attempt to add credits.
It is...incredible how many there are. Stripe does far too little in my opinion to help prevent issues like this, even though they have the business intelligence and enough data to do so.
by RALaBarge - I think Stripe does enough already. Fraud detection is a crapshoot regardless; I've had legitimate transactions rejected at random without explanation.by ronsor
- How can you verify, that the model that you are buying is the one that you are actually getting?by dmaa
- You basically can't. This episode from Syntax[0] shows one provider that he tried to go through to showcase this, and he was fairly certain it wasn't Claude, but of course that was all speculation on his part.by chrysoprace
- The reseller could use an intermediate proxy and modify the traffic like in [1], to get control of the client machine - depending on the harness permissions.
TLS terminates at the proxy (say, https://reselltokens.ai), end to end integrity is not enforced. LLM traffic contains tool calls like "bash ...", which are executed on the client machine, they can be manipulated. Secret exfil is also possible.
by veganmosfet - Nice, he can help fix my Linux Bluetooth audio issues.by andai
- they have no reason to do that to harm their reputation if their goal is profit, in which in this case it is.
- You can place your own CLIProxyAPI instance in front of the reseller proxy and block prompts/responses that look harmful.
There are community plugins like this: https://github.com/rheodev/cpa-plugin-privacyfilter
I haven't tried the plugin system myself yet.
by rdbell - that one platform is using a flipped chroma logo - chroma has nothing to do with this racket (source : i’m chroma’s ceo)by jeffchuber
- This research is way toooo shallow. He really should go check out linux.do or nodeseek.com — token resale economy there is truly breathtaking.
Edit: https://vectoral.com/blog/token-relay-market mentioned in comment.
by Sha1rholder - This was specifically meant to be about the ai credit resellers, not the relays themselves. I put together another piece here: https://vectoral.com/blog/token-relay-market that tackles that side of the market.by mlenhard
- Wait a sec, I have to trust a third party with basically no reputation, did I get it right?
It's basically asking for being hacked and/or sending you private data to random email addresses! Neither at a 99% discount I'd do it.
I understand if someone, for any reason, cannot access a specific model ... But nowadays, there are so many alternatives that even this doesn't make sense any more.
by vb-8448 - I'd rather trust a third party with no reputation than a well known Misanthropic company led by a man whose wife was asking Epstein for investment. They are even less trustworthy then ClosedAI.by miroljub
- I mean reselling items bought with stolen credit cards have been a thing for at least 20 yearsby charlieyu1
- So what? The world is more trustworthy than you can imagine. I have bought over 30 GPUs over the internet, sight unseen. From around the world and every single one has arrived good. I have also gotten over 20 from marketplace and the same. Use your common sense, from conversation and everything else, you can often separate the scammers from real folks.by segmondy
- The article indicates that the provided API key is probably a proxy to the actual so the third party is also recording all prompts made using the proxy key.by voidmain0001
- I expect most of the use to be for bulk data processing or desperate founders who don't care, not for agentic coding use at promising startups.
If your startup needs to run a million records of something, especially public data, through an LLM to extract the data you need, using bootleg tokens to shrink the bill starts feeling tempting.
If you're concerned about the data leaking, the biggest risk is that the API backends are quietly routing your requests to a cheaper model. You might be trying to buy Opus tokens but get Deepseek Flash responses.
by Aurornis - It's really common in China where OpenAI and Anthropic models are firewalled. There was a joke that Chinese people didn't realize how cheap DeepSeek was, because they already were using resold ChatGPT/Opus tokens at that price.
Here is a more detailed article about how it works:
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
by raincole - Distillation is one of the most unique and interesting aspects of this.
But otherwise, if a company gives something valuable for creating an account on their platform, expect that people will automate the creation of millions of accounts. If employees of B2B partners get benefits, they will resell them. Accounts will be hacked and resold. The same basic abuse patterns are decades old for online delivery services, loyalty accounts for airline and hotels, etc. There are entire industries dedicated to those spaces as well: large organizations with physical offices, hundreds of employees, HR departments, etc. dedicated to reselling digital benefits on grey markets.
Some companies are tolerant of allowing this to happen. The pessimistic view is that even illegitimate traffic contributes to the KPIs that your investors care about. The slightly less pessimistic view is that fraud prevention will always have trade-offs and false positives, and sometimes the savings of preventing fraud are genuinely outweighed by the false positives. Or maybe it's just Hanlon's razor and they truly never saw it coming.
- The comments here are baffling. Is nobody seeing the easy opportunity for gathering amazing high-quality training data by inserting yourself as a MITM? If I were a competing lab, criminal, or opportunist I'd lie/cheat/steal/simply pay the difference to get the chance to listen into real life scenarios of usage of modern models in a high-impact business.
Seems a huge part of the story completely absent to me.
by loufe - Isn’t that essentially OpenRouter and Cursor play.by tiffanyh
- They are just offering API key swaps, not switching endpoints. No scope for mitm there. I'm sure users would only trust API key swaps, if only to be sure what models are actually being served
- This is what every chinese "credit reseller" is doing, selling all the prompts and responses to labs in addition to selling quanted kimi/ds/etc as opus/fableby kay_o
- There's a strong theory with some rumors to support it that some of the largest customers of these services are labs doing distillation. The resellers are basically crowdsourcing the farming of accounts for them to use.
Doing MITM on other people's sessions isn't as interesting as simply sending your own synthetic requests to the models at a 97% discount. They manufacturer the questions and responses they want to train on.
by Aurornis - The original article linked in the opening has more context https://vectoral.com/blog/token-relay-market
People trading their unused credits feels more genuine, although still in violation of the agreements. The person who got into YC Startup School who was trying to resell the $2500 of credits was interesting. It wouldn’t be that hard for OpenAI to identify the IP addresses of the relays and start flagging accounts, tracing it back to the source. Risking burning your bridges with YC for a relatively small profit is a questionable decision.
The original article showed discounts ranging all the way up to 98%. At those levels it’s obviously not people reselling anything. It’s either sourced from stolen API keys, bought with stolen credit cards, or acquired through automated sign up of trial accounts if you’re actually getting the API you request.
I would expect a lot of them are reselling a different API. Sign up for Anthropic tokens and get Deepseek responses instead.
by Aurornis