back
136 comments
I spent years working on financial integrity at a large ads company and this isn't novel at all! The same resale markets are at play for the last generation of internet giant's products. Highly sophisticated actors, able to cobble together impressions through abuse of the billing systems, stolen financial instruments, taken over accounts, etc, create massive markets of discounted impressions for resale. It was very interesting to compete against them as we hardened our defenses and they invented new ways to exploit them. I imagine the same defensive tools and techniques are being deployed by my former colleagues who moved to the labs.
Yes, and I'm reminded of Bitcoin miners relocating for subsidized electricity or even stealing it outright.
One aspect that seems to be missing is the abuse of the free credits provided for new companies by AWS, Azure, and other providers.

I know of a friend's company in India who purchased inference, at 4% of the actual price and states that it gave him an unbeatable competitive edge in their large running video influence pipelines. Any new competitors could not offer their pricing at all.

Primarily that operated because registering a new company getting free AWS credits was a very tiny cost

I was going to cover this in a follow-up article, but yeah, there are network of token brokers who buy unused credits from startups and then resell them.
A bit like setting up a supermarket that just sells another competing supermarket's "free fruit for kids" fruit.
I should have added that I ran my first startup in India for 8 years before moving to the states, that's why I have an insider view.
the in India wasnt even needed no worries
Video influence pipelines from India huh?

No wonder social media is so shit nowadays. All that brainwashing and propaganda from third world countries, now at 4% the price!

The real problem is subscription models. Businesses want recurring revenue so they try to game the ratio of fixed subscription prices to COGS but it's always a game and so whoever can figure out the upside for the company can figure out the complementary upside for themselves.

How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.

Fixed cost per token simply works.

The abuse is factored in to pricing and quota structure.

I have some past experience with subscription plans for a much less interesting product. Abuse is inevitable. As you do your math on the subscription costs you look at the actual usage across all accounts, which includes the abuse.

Cleaning up abuse was still a priority because it meant we could give more service to the real customers. It's a frustrating battle because you actually want to give good service to the real customers, but you also want to let each account do as they please with their susbcription. That latter priority probably fades fast for something like an LLM company when you discover that the abuse has become automated and is scaling up so fast that it's tilting the math toward degrading service for everyone.

> Fixed cost per token simply works.

As a consumer, I benefit greatly from the subscription rates. There's a lot of grumbling about how they should go to fixed token for everyone but I'm over hear happy with the subscription plan offerings while they last.

Subscription models are fine if profitable individually. It then is an automated token allocation.

The problem is loss making subscription as a marketing tool. But if you do loss leaders that be the risk you take.

> How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.

reverse the pricing structure; give modest discount once you go over certain amount of tokens, then you are incentivized NOT to start multiple accounts.

require first few transactions to be pre-paid to get around at least some of the card problems.

Of course, that would fuck over subsidized plans, but I don't see any option to keep them if you want to avoid the flood

It's the same fundamental problem as "ticket touting" for popular events - if you sell something that's in demand at a price that's far lower than the clearing price of the market, you're creating a juicy arbitrage opportunity that sooner or later somebody is going to try and exploit
Not necessarily.

What OpenAI and Anthropic are selling — a flat-rate subscription with both 5-hour and weekly rate limits — is a bit like an all-you-can-eat buffet.

They expect some customers to generate more in costs than they bring in revenue, just like some people at the all-you-can-eat buffet eat more than they pay for, but by the law of large numbers, the mean cost per customer comes out to something the labs are comfortable with.

What the resellers are doing is undermining the labs' assumptions that every person needs to eat and sleep, and hence won't use every 5-hour window to the fullest. It's the equivalent of buing the all-you-can-eat pass for one person, coming into the restaurant with three of the largest suitcases you can find, and filling them to the brim with food, which you later re-sell at much lower prices. In other words, fraud.

Yeah but those tickets are never a loss leader. So it feels different.

This is more like sharing Argentinan $2/m Google Premium subscriptions via a load balancer.

This is the problem we've been working on solving with WorkOS Radar. We run it for Cursor and a bunch of other AI companies who have a free trial that gives some free inference to test the product.

It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.

https://workos.com/radar

(If you'd like to work on this, we are hiring :))

I don't think device fingerprinting is the right approach here.

Client-side detection can always be sidestepped, and you need to intermediate the actual inference to get enough signals to make an accurate prediction. There are hundreds of listings for cursor tokens/credits right now.

We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.

the way i see it there are 3 types of resellers. the ones using fake credit cards to rack up costs and then cancel the card are doing actual fraud. then you got mass free trial abuse which is more of a gray area and i would say its still wrong. but if you sign up for a subscription, pay for it and resell your monthly tokens thats not at all unethical, even if its breaking their terms and costing the provider money.

imagine ford starts renting out company cars at a huge discount so they can get people to buy the same model for themselves after they drive it at work. its the exact same car and costs the same amount to make, they just take a loss on it and use by anyone other than employees is banned in the contract.

some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash. is that fraud? it costs ford nothing because they get the same payments either way, they just lose potential profits. they are the ones who decided to set up a loss leader and take the risk of someone "abusing" the system so we dont need to use public resources to defend their strategy. that wastes taxpayer money to protect corporate profits, and it creates moral hazard because ford (anthropic) is not the one paying for enforcement.

> some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash. is that fraud?

Most likely, yes.

There's a common fallacy that once you pay someone for a service, you are free to do whatever you want with that service. In the case of the rental car, the contract the company entered into would prohibit reselling the services and limit who can drive them and for what purposes.

Some people see these limitations and scream "Not fair! They paid money, they can do whatever they want!" The misunderstanding is that the price they paid was predicated on the specific use. They got a lower price for the rentals because the provider calculated the expected use case and priced it according to that.

If the small company starts renting out the cars to try to maximize how much they're used, that breaks the financial model. That's why this type of use is forbidden in every basic rental contract.

It's the same reason why you can't rent an apartment building and then turn it into an AirBnB. On a smaller scale, it's why you can't go to an all-you-can-eat buffet and load up on food to carry outside to your 5 hungry friends. This type of pricing is everywhere.

There is a vocal online minority who believe user license agreements shouldn't be enforced and individuals should never be considered accountable for following them, but that doesn't even apply to these resellers. This isn't a lowly individual user trying to get back $10 from their $20 per month plan that was going unused. There's no way to even achieve the scale and discounts without mass, automated fraud. They're doing chargeback fraud or using stolen credit cards.

It's not even a crime where the big corporation is the only victim. The higher the volume of fraud on the subscription accounts, the less real usage you and I get for our dollar. These people are jumping on the accounts targeted to individuals like us and abusing them to sell tokens to big corporations trying to abuse them at scale. People like you and I lose when these accounts get their limits reduced or the companies start introducing ID checks and KYC just to use basic services.

Seems to be an LLM megaexpansion of the actual source (in chinese): https://www.v2ex.com/t/1196011
How do the users know they're getting what they're paying for?

I disabled automatic downgrading/rerouting because it sometimes takes me a second to tell when the answer came from a different model than I wanted. You could easily sell Opus as Fable for a good while.

> For example, one operator’s price-comparison site listed a package that bought the equivalent of $3,333 worth of official Anthropic credit for 425 RMB — roughly $0.13 of usage per $1 spent.

Do these numbers make sense? $0.13 usage per $1 spent?

This is pretty fascinating!

Here are the two open source proxies listed in the article: https://github.com/songquanpeng/one-api and https://github.com/QuantumNous/new-api

Ah I was wondering how a certain chinese site I came across did this and it could be this.

That site offers substantial free tokens, is often reported as being flaky and their affiliate links are popping up on different social medias but look sketchy as anything.

Nice research and structuring into 4-tier layer. For providers like Anthropic and OpenAI, subscription is the entry point for all these, right? Besides the measures proposed in the article, can token usage % determine these clusters of accounts?
wow. Ai providers can't solve fraud 101 with their oh-so-dangerous-if-released-models?

i think this alone is the biggest bear signal

thats one of the reasons why we vest any of our new customers. We need to know you before you are allowed to use our agent system. When you have an open sign up with some free credits, all hell breaks loose.
This is more concerning to me from the perspective of being able to appear as "multiple entities" to the frontier models. My question is do the companies know and are able to detect and consolidate all these accounts as a single actor and just don't care to combat it? Or are they unable to detect this? And if they are unable to detect it wouldn't it be pretty trivial to use this to influence the model overall? I would think there's more money in using it that way.
Don't the operators store the agent traces and resell them as training data to AI companies? Why wasn't this mentioned? Did you find any evidence of that?
If we compare OpenAI subscription prices vs. the cheapest inference providers on OpenRouter, than OpenAI must be losing money. Add the fraud to this and the question is what the future will hold. The only salvation is hardware getting 10x cheaper before the labs run out of money. Otherwise, we'll lose affordable access to bulk tokens.
I use both of subscription and API services. on last month, i chat with CLI and let it to do something. After that, maybe in one days pass, i received the $32 USD bill. it cause my left my API key and CLI call the API to do job not through subscription.
Aren't these figures the wrong way around

"$0.13 of usage per $1 spent"

So I spend a dollar and I get 13 cents worth of usage?

I guess it means the otherway around but I'm not seeing how that phrasing works. Are they paying a premium to access US models?

How do you know the reseller is even giving you the genuine article? Could they be advertising Fable but repacking Deepseek?
The relays sound also like a nice source of monitoring for whoever controls them.
How do the distillation buyers know it's real? Heard that these sort of markets are fond of silently substituting inferior models. i.e. sonnet instead of opus etc.

Not unlike narcotics being cut with filler

"Token reseller market" is a fancy way of saying credit card fraud. If someone stole xboxs from stores using stolen credit cards and then sold them at 10% of their price, at what point is it a "resller market" and not "criminal enterpirse"?
This article is about the mechanics, but the title implies this is unethical. Why is this practice considered unethical?
what tokens are these being sold?
Token is the new cryptocurrency.
How do we define "fraud" if taking a new user discount over and over is fraud?
The chinese AI and greymarket peptides scenes feel so vital, fun and wild-west. Imagine spending your life being beholden to USA corporations and being scolded on HN for violating a trillion dollar company’s ToS.
I don't know anything about tokens. Does the following argument make sense?

1. Tokens are model-specific: e.g. tokens used by Anthropic cannot be used in models of other companies.

2. Tokens are generated by GPU cards. They measure the power of GPU cards.

3. Tokens cannot be separated from the models. You sort of "connect" the software part (models) into the hardware part (GPU cards) to use the tokens generated from the hardware.