Inside the AI Token Relay Market: Cheap Inference, Account Pools, and Fraud
Lead
As model APIs become a core unit of AI infrastructure, a gray market has emerged around the resale of tokens. Security researcher Matt Lenhard describes a relay ecosystem, visible in Chinese-language forums and price directories, that packages access to U.S. model providers into low-cost API services for downstream buyers.
Key points
- The pricing is far below official rates. The post cites one package that offered the equivalent of $3,333 in official Anthropic credit for 425 RMB, or roughly $0.13 of official usage per $1 spent. Among tracked relays, the largest listed discount reached 97.8% below official pricing.
- The ecosystem has layers. Upstream card and account merchants provide virtual credit cards and bulk-registered accounts. Midstream account pools aggregate credentials, manage tokens and rate limits, and fail over when accounts are flagged. Downstream relays wrap that access in Chinese-language products with billing, recharge, support groups, and price competition. End users include individual developers, startups, SaaS companies, and some commercial buyers pursuing model distillation.
- The software is ordinary gateway software. Many relays reportedly run on one-api or new-api, both OpenAI-compatible gateways. These tools can be legitimate when used to manage a company’s own accounts and quotas. The boundary is crossed when operators fill channels with stolen, leaked, abused, or contract-violating keys and resell them.
- Abuse methods vary. The article lists mass free-trial creation, chargebacks, stolen or prepaid cards, proxying through weakly protected chatbots, and “denial of wallet” attacks that burn a provider’s budget with concurrent requests.
- The market looks mature. The researcher observed comparison sites, affiliate programs, gateway products, and even daily API-key giveaways. The ten highest-traffic relays tracked in the article were said to draw about 3.6 million monthly visits combined.
Why it matters
The most important signal is not a single exploit, but the industrialization of token arbitrage. If model providers tighten KYC and payment controls, abuse may migrate to the application layer, where consumer AI products expose valuable model access but may have weaker rate limits, bot detection, or identity checks.
For developers, relay APIs may look like a cheap shortcut, but they carry risks: instability, privacy exposure, legal uncertainty, and sudden shutdowns. For model labs and AI app companies, the defense surface is expanding from account fraud to traffic analysis, key leakage, refund abuse, reseller detection, and supply-chain visibility. Tokens are becoming financialized infrastructure, and protecting them increasingly resembles fraud prevention in payments.
Source: Hacker News
Comments
Checking sign-in status...
Loading comments...