I spent years working on financial integrity at a large ads company and this isn't novel at all! The same resale markets are at play for the last generation of internet giant's products. Highly sophisticated actors, able to cobble together impressions through abuse of the billing systems, stolen financial instruments, taken over accounts, etc, create massive markets of discounted impressions for resale. It was very interesting to compete against them as we hardened our defenses and they invented new ways to exploit them. I imagine the same defensive tools and techniques are being deployed by my former colleagues who moved to the labs.
One aspect that seems to be missing is the abuse of the free credits provided for new companies by AWS, Azure, and other providers.
I know of a friend's company in India who purchased inference, at 4% of the actual price and states that it gave him an unbeatable competitive edge in their large running video influence pipelines. Any new competitors could not offer their pricing at all.
Primarily that operated because registering a new company getting free AWS credits was a very tiny cost
I was going to cover this in a follow-up article, but yeah, there are network of token brokers who buy unused credits from startups and then resell them.
Some countries have more complexity to registering a new company than others, and perhaps it’s the establishment of a new legal entity that is an unlocker to the free credits.
I don’t know if that’s true of India or not, but I like to give comment authors the benefit of the doubt that being specific about the geography was helpful context here
The real problem is subscription models. Businesses want recurring revenue so they try to game the ratio of fixed subscription prices to COGS but it's always a game and so whoever can figure out the upside for the company can figure out the complementary upside for themselves.
How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
> How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
reverse the pricing structure; give modest discount once you go over certain amount of tokens, then you are incentivized NOT to start multiple accounts.
require first few transactions to be pre-paid to get around at least some of the card problems.
Of course, that would fuck over subsidized plans, but I don't see any option to keep them if you want to avoid the flood
This is the problem we've been working on solving with WorkOS Radar. We run it for Cursor and a bunch of other AI companies who have a free trial that gives some free inference to test the product.
It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.
I don't think device fingerprinting is the right approach here.
Client-side detection can always be sidestepped, and you need to intermediate the actual inference to get enough signals to make an accurate prediction. There are hundreds of listings for cursor tokens/credits right now.
We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.
How do the users know they're getting what they're paying for?
I disabled automatic downgrading/rerouting because it sometimes takes me a second to tell when the answer came from a different model than I wanted. You could easily sell Opus as Fable for a good while.
> For example, one operator’s price-comparison site listed a package that bought the equivalent of $3,333 worth of official Anthropic credit for 425 RMB — roughly $0.13 of usage per $1 spent.
Do these numbers make sense? $0.13 usage per $1 spent?
Yeah, I should probably clean this up. The sentence is a bit hard to understand. What I was trying to show was the steep discounts offered by resellers.
That sounds entirely plausible. When I was on the Claude Max $100 plan, I would often get the equivalent of at least $1300 API usage, according to the costs counter in Claude Code. That would be about $1 of usage for every $0.075c.
At $1 of usage for $0.13, the reseller is making a tidy profit on top of whatever subscriptions they're reselling.
If you are using a stolen credit card to buy tokens and resell them, then the cost per token is the amount the credit card cost you (and building/running the proxy service), not the value of the tokens themselves.
Nice research and structuring into 4-tier layer. For providers like Anthropic and OpenAI, subscription is the entry point for all these, right? Besides the measures proposed in the article, can token usage % determine these clusters of accounts?
I use both of subscription and API services. on last month, i chat with CLI and let it to do something. After that, maybe in one days pass, i received the $32 USD bill. it cause my left my API key and CLI call the API to do job not through subscription.
thats one of the reasons why we vest any of our new customers. We need to know you before you are allowed to use our agent system. When you have an open sign up with some free credits, all hell breaks loose.
"Token reseller market" is a fancy way of saying credit card fraud. If someone stole xboxs from stores using stolen credit cards and then sold them at 10% of their price, at what point is it a "resller market" and not "criminal enterpirse"?
These aren't stolen credit cards. This hack works by maxing out subscription limits of the Anthropic/OpenAI plans, so you never pay additional API fees. It's fraud but not theft.
I don't doubt that stolen cards are involved, but you could say that for anything that has to do with card-not-present transactions, e.g. Amazon retail. Is there reason to believe that it's especially prominent in this case?
I assume most of it is just people who want cheaper access to these models and don't mind subsidizing access via somebody who is simultaneously distilling the model.
What?! It is definitely credit card fraud, and a criminal enterprise, and by any definition it is wrong. I cannot imagine a jurisdiction where this is a “mere breach of contract”.
Where are you getting the idea that the cards are stolen? Sure it's mentioned that some of them likely are, but there's no reason to believe that that's most of them or that the fact that they're stolen has anything to do with the way this market functions.
This is about controlling who gets to use the tokens for what, not about payment fraud.
It's not _theft_ because nothing is _stolen_. The tokens are being used in a way that breaches the contract agreed to by whomever set up the account with OpenAI, Anthropic, Kilo, Antigravity etc. but it's not theft.
Right, theft requires that there be somebody who no longer has access. This is about too many people having access. Piracy might be a more fitting term.
Are we reading the same article? That's mentioned once, as a potential alternative, nested in a bulleted list of alternatives. This is not an article about credit card fraud.
This is about people circumventing the model company's attempts to protect their intellectual "property" (which, if you insist on that incoherent usage of the word "property", they themselves stole from the rest of us).
It's equivalent to buying a DVD in the US which is region-locked to Asia. Grey market, not black market. If you use a stolen credit card to buy that DVD, well tat's a totally separate matter.
I don't know anything about tokens. Does the following argument make sense?
1. Tokens are model-specific: e.g. tokens used by Anthropic cannot be used in models of other companies.
2. Tokens are generated by GPU cards. They measure the power of GPU cards.
3. Tokens cannot be separated from the models. You sort of "connect" the software part (models) into the hardware part (GPU cards) to use the tokens generated from the hardware.
Tokens measure "how much work the model did" in the same way that step counts measure "how far the person went"
GPUs "generate tokens" in the same sense that human feet "generate steps"
You can't compare token counts across different providers to get an absolute measure of "total work done" for the same reason that you can't compare step counts across different people to get an absolute measure of "total distance traveled"
Aren't these figures the wrong way around
"$0.13 of usage per $1 spent"
So I spend a dollar and I get 13 cents worth of usage?
I guess it means the otherway around but I'm not seeing how that phrasing works. Are they paying a premium to access US models?
I spent years working on financial integrity at a large ads company and this isn't novel at all! The same resale markets are at play for the last generation of internet giant's products. Highly sophisticated actors, able to cobble together impressions through abuse of the billing systems, stolen financial instruments, taken over accounts, etc, create massive markets of discounted impressions for resale. It was very interesting to compete against them as we hardened our defenses and they invented new ways to exploit them. I imagine the same defensive tools and techniques are being deployed by my former colleagues who moved to the labs.
One aspect that seems to be missing is the abuse of the free credits provided for new companies by AWS, Azure, and other providers.
I know of a friend's company in India who purchased inference, at 4% of the actual price and states that it gave him an unbeatable competitive edge in their large running video influence pipelines. Any new competitors could not offer their pricing at all.
Primarily that operated because registering a new company getting free AWS credits was a very tiny cost
I was going to cover this in a follow-up article, but yeah, there are network of token brokers who buy unused credits from startups and then resell them.
Video influence pipelines from India huh?
No wonder social media is so shit nowadays. All that brainwashing and propaganda from third world countries, now at 4% the price!
the in India wasnt even needed no worries
Some countries have more complexity to registering a new company than others, and perhaps it’s the establishment of a new legal entity that is an unlocker to the free credits.
I don’t know if that’s true of India or not, but I like to give comment authors the benefit of the doubt that being specific about the geography was helpful context here
The real problem is subscription models. Businesses want recurring revenue so they try to game the ratio of fixed subscription prices to COGS but it's always a game and so whoever can figure out the upside for the company can figure out the complementary upside for themselves.
How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
Fixed cost per token simply works.
> How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
reverse the pricing structure; give modest discount once you go over certain amount of tokens, then you are incentivized NOT to start multiple accounts.
require first few transactions to be pre-paid to get around at least some of the card problems.
Of course, that would fuck over subsidized plans, but I don't see any option to keep them if you want to avoid the flood
> You can't forbid automation because sub-agents are automation.
Is this some kind of attempt to make the other side look better by making the worst argument you can?
This is the problem we've been working on solving with WorkOS Radar. We run it for Cursor and a bunch of other AI companies who have a free trial that gives some free inference to test the product.
It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.
https://workos.com/radar
(If you'd like to work on this, we are hiring :))
I don't think device fingerprinting is the right approach here.
Client-side detection can always be sidestepped, and you need to intermediate the actual inference to get enough signals to make an accurate prediction. There are hundreds of listings for cursor tokens/credits right now.
We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.
How do the users know they're getting what they're paying for?
I disabled automatic downgrading/rerouting because it sometimes takes me a second to tell when the answer came from a different model than I wanted. You could easily sell Opus as Fable for a good while.
> For example, one operator’s price-comparison site listed a package that bought the equivalent of $3,333 worth of official Anthropic credit for 425 RMB — roughly $0.13 of usage per $1 spent.
Do these numbers make sense? $0.13 usage per $1 spent?
I think this was very poorly worded. I believe they’re trying to say you pay the reseller $0.13 to get what costs $1 at the upstream provider.
Also 425 RMB is about $59 so $1 of tokens for $0.017 not $0.13 (the discount rate quoted also seems off).
seems like they missed a zero somewhere. its a dollar of usage for a penny and change.
Yeah, I should probably clean this up. The sentence is a bit hard to understand. What I was trying to show was the steep discounts offered by resellers.
So $1 of usage for $0.13?
That sounds entirely plausible. When I was on the Claude Max $100 plan, I would often get the equivalent of at least $1300 API usage, according to the costs counter in Claude Code. That would be about $1 of usage for every $0.075c.
At $1 of usage for $0.13, the reseller is making a tidy profit on top of whatever subscriptions they're reselling.
If you are using a stolen credit card to buy tokens and resell them, then the cost per token is the amount the credit card cost you (and building/running the proxy service), not the value of the tokens themselves.
This article is about the mechanics, but the title implies this is unethical. Why is this practice considered unethical?
Nice research and structuring into 4-tier layer. For providers like Anthropic and OpenAI, subscription is the entry point for all these, right? Besides the measures proposed in the article, can token usage % determine these clusters of accounts?
There are probably various metrics like language used to prompt the model, number of hours per day spent prompting, and many others.
There are quite a few other mitigations that could be done by providers that aren't mentioned in the article.
I use both of subscription and API services. on last month, i chat with CLI and let it to do something. After that, maybe in one days pass, i received the $32 USD bill. it cause my left my API key and CLI call the API to do job not through subscription.
thats one of the reasons why we vest any of our new customers. We need to know you before you are allowed to use our agent system. When you have an open sign up with some free credits, all hell breaks loose.
what tokens are these being sold?
Token is the new cryptocurrency.
token is the new... token!
You are shadowbanned, apparently since you tried to spam links to your own site calling it an archive.
"Token reseller market" is a fancy way of saying credit card fraud. If someone stole xboxs from stores using stolen credit cards and then sold them at 10% of their price, at what point is it a "resller market" and not "criminal enterpirse"?
These aren't stolen credit cards. This hack works by maxing out subscription limits of the Anthropic/OpenAI plans, so you never pay additional API fees. It's fraud but not theft.
With theft, somebody ends up without an Xbox. Theft is wrong. This is mere breach of contract, whether it's wrong depends on the contract.
You’ll have to clarify who the counterparties are to this contract and where the person whose credit card was stolen fits into it.
I don't doubt that stolen cards are involved, but you could say that for anything that has to do with card-not-present transactions, e.g. Amazon retail. Is there reason to believe that it's especially prominent in this case?
I assume most of it is just people who want cheaper access to these models and don't mind subsidizing access via somebody who is simultaneously distilling the model.
What?! It is definitely credit card fraud, and a criminal enterprise, and by any definition it is wrong. I cannot imagine a jurisdiction where this is a “mere breach of contract”.
Where are you getting the idea that the cards are stolen? Sure it's mentioned that some of them likely are, but there's no reason to believe that that's most of them or that the fact that they're stolen has anything to do with the way this market functions.
This is about controlling who gets to use the tokens for what, not about payment fraud.
What?
It's not _theft_ because nothing is _stolen_. The tokens are being used in a way that breaches the contract agreed to by whomever set up the account with OpenAI, Anthropic, Kilo, Antigravity etc. but it's not theft.
Right, theft requires that there be somebody who no longer has access. This is about too many people having access. Piracy might be a more fitting term.
The credit card and the money is what was stolen.
Are we reading the same article? That's mentioned once, as a potential alternative, nested in a bulleted list of alternatives. This is not an article about credit card fraud.
This is about people circumventing the model company's attempts to protect their intellectual "property" (which, if you insist on that incoherent usage of the word "property", they themselves stole from the rest of us).
It's equivalent to buying a DVD in the US which is region-locked to Asia. Grey market, not black market. If you use a stolen credit card to buy that DVD, well tat's a totally separate matter.
Fair enough. Is the right enforcement then to ignore the "token resellers" and go after the credit card business listed at the "upstream" on his post?
I don't know anything about tokens. Does the following argument make sense?
1. Tokens are model-specific: e.g. tokens used by Anthropic cannot be used in models of other companies.
2. Tokens are generated by GPU cards. They measure the power of GPU cards.
3. Tokens cannot be separated from the models. You sort of "connect" the software part (models) into the hardware part (GPU cards) to use the tokens generated from the hardware.
Tokens measure "how much work the model did" in the same way that step counts measure "how far the person went"
GPUs "generate tokens" in the same sense that human feet "generate steps"
You can't compare token counts across different providers to get an absolute measure of "total work done" for the same reason that you can't compare step counts across different people to get an absolute measure of "total distance traveled"
No, all 3 points are incorrect. I’m not even pro-LLM and I’ll tell you this.
You should do a bit of reading on what a token is. The short answer is that it’s a series of 2-4 bytes of information turned into an integer.
Your comparisons are akin to asking “are amazon gift cards the same as a bunch of pesos?”