The AI Credit Resale Economy
vectoral.com
vectoral.com
People trading their unused credits feels more genuine, although still in violation of the agreements. The person who got into YC Startup School who was trying to resell the $2500 of credits was interesting. It wouldn’t be that hard for OpenAI to identify the IP addresses of the relays and start flagging accounts, tracing it back to the source. Risking burning your bridges with YC for a relatively small profit is a questionable decision.
The original article showed discounts ranging all the way up to 98%. At those levels it’s obviously not people reselling anything. It’s either sourced from stolen API keys, bought with stolen credit cards, or acquired through automated sign up of trial accounts if you’re actually getting the API you request.
I would expect a lot of them are reselling a different API. Sign up for Anthropic tokens and get Deepseek responses instead.
But also, resellers only need to make an overall profit including kickbacks from the companies purchasing token history for distillation.
I suspect it's closer to the sub price and anthropic is just milking their API users, but that's something you'd only know from the inside
How so?
Didn’t see it, but it’s obvious in retrospect. Thanks!
But the API price is likely simply regular supply and demand, charging as much as the market will pay. Corporations are dropping insane amounts because it's still peanuts for many industries. Software has just been ridiculously cheap before AI. So high prices are still low for companies if it eases some bottlenecks.
YC has advised startups in the past that it's easier to sell a single $100k customer than 100 $1k customers.
It would also be relatively surprising to learn that i.e. the Chinese providers are OOMs better at inference than OAI/Anthropic (like their prices would imply if they were in a perfectly competitive market).
DeepSeek's price hike is mostly driven by increased demand, for example. It's not about losses so much as they don't have enough infrastructure and need to reduce demand somehow.
https://www.dbresearch.com/PROD/IE-PROD/PDFVIEWER.calias?pdf...
People have been talking about late capitalism in the west for a century. The Chinese state would argue that we cannot be in late capitalism because we're actually in the first stage of socialism, and the people would wonder how we got to late capitalism when they never got to experience early or middle capitalism. But really the only thing we know that definitively does not work is implenting Marxism and Marxism-Leninism and Maoism and its offshoots as doctrine. Whether that means that the default is a prescriptive version of capitalism is, well, open to debate, and probably too simplistic.
Like the 10th Rule of Acquisition says, greed is eternal. Structures and behaviors that flow down from this tend to be the same everywhere.
Given their past history and current geopolitics, I'd be willing to bet this is more likely than not.
There is no “real cost” other than the cost actually charged.
Define cost: Is it only the inference cost to the provider, or do you also consider training costs as well?
If it's the latter, how would you estimate the number of total tokens that will be sold for the current model (so that we can calculate marginal cost)?
this is all it is. it's not complicated.
It's just reselling.
Maybe people are starting to copy Anthropic's rhetoric of "everything that inconveniences me is fraud (e.g. distillation). Everything that benefits me is legit."
Signing up to the startup credit programs with fake startups is fraud.
In general, performing a misrepresentation to deceive another party for financial gain is fraud. So there are plenty of ways to define this as fraud
Signing up for it on a website and checking a box that says "I agree to the terms of service", I don't think carries the same weight. But maybe that's just me.
Seems a huge part of the story completely absent to me.
Doing MITM on other people's sessions isn't as interesting as simply sending your own synthetic requests to the models at a 97% discount. They manufacturer the questions and responses they want to train on.
But otherwise, if a company gives something valuable for creating an account on their platform, expect that people will automate the creation of millions of accounts. If employees of B2B partners get benefits, they will resell them. Accounts will be hacked and resold. The same basic abuse patterns are decades old for online delivery services, loyalty accounts for airline and hotels, etc. There are entire industries dedicated to those spaces as well: large organizations with physical offices, hundreds of employees, HR departments, etc. dedicated to reselling digital benefits on grey markets.
Some companies are tolerant of allowing this to happen. The pessimistic view is that even illegitimate traffic contributes to the KPIs that your investors care about. The slightly less pessimistic view is that fraud prevention will always have trade-offs and false positives, and sometimes the savings of preventing fraud are genuinely outweighed by the false positives. Or maybe it's just Hanlon's razor and they truly never saw it coming.
It's basically asking for being hacked and/or sending you private data to random email addresses! Neither at a 99% discount I'd do it.
I understand if someone, for any reason, cannot access a specific model ... But nowadays, there are so many alternatives that even this doesn't make sense any more.
If your startup needs to run a million records of something, especially public data, through an LLM to extract the data you need, using bootleg tokens to shrink the bill starts feeling tempting.
If you're concerned about the data leaking, the biggest risk is that the API backends are quietly routing your requests to a cheaper model. You might be trying to buy Opus tokens but get Deepseek Flash responses.
Maybe this make sense, but anyway I have to pay a lot of attention at the output I get. Eg: who guarantees there is no prompt/sql injection? Especially if I have to load the output in some internal system.
I mean someone could try to sneak prompt injection into a text field, but the people buying black market resale tokens from third parties aren’t thinking about anything other than getting cheap output.
FTFY.
Here is a more detailed article about how it works:
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
You have no way to verify that your data is not sold to someone else, send to the provider you think, or the response is genuine and not full of prompt injections or other stuff!
Edit: https://vectoral.com/blog/token-relay-market mentioned in comment.
TLS terminates at the proxy (say, https://reselltokens.ai), end to end integrity is not enforced. LLM traffic contains tool calls like "bash ...", which are executed on the client machine, they can be manipulated. Secret exfil is also possible.
There are community plugins like this: https://github.com/rheodev/cpa-plugin-privacyfilter
I haven't tried the plugin system myself yet.
Since it modifies logic across the full request/response lifecycle, I unfortunately couldn't implement it cleanly with the existing plugin API.
It is...incredible how many there are. Stripe does far too little in my opinion to help prevent issues like this, even though they have the business intelligence and enough data to do so.
Demo accounts
Free trials
Unlimited chat relays (eg chatgpt chat)
Leaked company credentials
Etc
so to a startup - you can trade your credits - then get actual cash.
just like you would if trading debt etc.
A simpler explanation is that that this is just a resale market.
Some of the abuse is more benign, but there is also real fraud through chargebacks, account takeovers, and stolen credit cards.
Also, outside the labs, most of the companies I've talked with have shut off free tiers and free credits entirely because the abuse is so bad.
Not sure is this what they meant by the great “ai wealth redistribution”.
With Grok being half-priced for indian residents, I would not be shocked to see a parallel indian account resell economy coming.
At first I thought it was so people could steal the traces, but now I wonder if this isn't just laundering startup credits for dollars.
You can easily find them in Chinese tech forum linux.do
It's not exactly "underground" if they clearly advertising public channels out in the open.
Searching for "cheap AI credits" on Google returns none of these sites, or any in fact... on duckduckgo however, you get a lot of results.
The thing will eat itself unless the AI companies find a way to make money directly from it.
Especially for Claude because Anthropic is very good at identifying mainland Chinese and getting them banned in hours. There are many of them who are willing to pay more than the original rate for a stable experience.
It's very hard for them because they'll need a legit phone number and bank cards that are not issued in China, and a clean enough IP, etc. and those better match together to make sense. (Back in the day, ChatGPT required resident IPs, which made it worse, but they worry about growth more now). Obviously, they have to use a VPN to access the real Internet, and most of the IPs they can find are shared with bots and abusers.
These combinations are questionable and very easy to filter, probably with Luna/Haiku tier of models that are able to tell things might get fishy here, and it would likely escalate to heavier checks and trigger KYC or straight banning.
Those are only my guess and probably aren't how the system works, but I think these rules are fairly easy to come up with for developers who have any idea of anti-abuse. I've seen too many Chinese posts mourning their accounts and communicating that their setups there would be similar mechanisms, I would say.
In previous months, there was news that Claude Code uploading a special signal for the Chinese timezone is pretty evident. I probably got away from having serious insomnia, using PST on my computers, and exclusively speaking English with those models lol.
can't they detect if someone is reselling their tokens like this ? doesn't seem too hard
right. Abstractions taken to the max. When tech solves problems that only 0.001% care about. NFT smelt similar.
Join YC, get free shit from the network, profit. Nice.
Is that still a thing? I’ve thought they’ve discontinued the deals section. (There are a lot of other ways to get a startup grant, of course.)
1) Capitalism - Adam Smith, John Maynard Keynes (Keynesian Economics), etc., etc. in most places in the world...
2) Huge validated existing international market...
3) Multi-jurisdictional World... laws/statutory codes applicable to businesses in specific circumstances in one place may not be applicable to businesses in specific circumstances in another...
4) AI Tokens are a commodity; i.e., there is no chokepoint or monopoly controlled by one AI company in one jurisdiction, i.e., if one AI company makes rules unacceptable to a token consumer, that consumer can simply switch providers to another provider in another jurisdiction somewhere else in the world.
5) Tokens can be bought, sold, and resold at profit just like any other good or service.
6) Tokens can be bought from anywhere in the world and sold to anywhere in the world. Easily.
7) Tokens are a digital good, easy to scale, and do not require supply chains, lead times, labor, manufacturing, warehousing, shipping, going through geographic chokepoints, customs, etc., etc. -- all of the things that manufactured goods do.
8) Many people around the world want to make money or make more money... i.e., "economic incentive" (aka Capitalism's "profit motive")...
Well... add all of those together and what do you get?
You get buy/sell/trade forums/auctions/individuals/brokers/businesspeople -- around that market...
Just like you get those same things around every other market.
In this large multi-jurisdictional world, if one government makes all of that illegal in their country, then another government is going to be happily collecting all of the taxes from making all of that legal, in theirs!
If a given government makes trade illegal -- then they correspondingly lose the tax revenue...
Taxes and trade are intricately, intricately intertwined...
Could this business model be used for money laundering or other illegal activities?
Yes -- but any other business model could as well!
And, on the flip side, this business model could be accomplished legally/lawfully/morally/ethically -- just like any other business where there is an actual underlying value being exchanged.
Because, AI Tokens, if legally/lawfully/morally/ethically traded, do have underlying value...
In conclusion, at this point in time, I am neither for this business model nor against it...
But I think it'll be highly interesting to watch this space for the next couple of years, to see what happens, to see who does what, to see what plays out on the legal front, on the government front (foreign + domestic), on the media front, and on the technology front surrounding it...