ATRIUMsearch → argument graph
Video · 2026-08-07 · 23m · 5 moments

I had no idea there was a BLACK MARKET for AI Tokens

✦ AI generated

timeline · colored by role

01
Claim

There is a thriving black market for AI tokens where Chinese sellers offer access to popular LLM providers at a fraction of the cost.

The host introduces the black market for AI tokens, where Chinese sellers offer API access to services like Claude and OpenAI for a fraction of the official price, with some AI companies reportedly losing millions per month.

transcript

Wes: Did you know there's a black market for AI tokens? Chinese sellers are offering up API tokens and subscription to popular LLM providers like Cloud Code and OpenAI Codex for pennies on the dollar. >> I've heard stories of companies losing a million dollars a day. I heard through the grapevine of a coding agent, one of the more popular ones, that's currently losing 10 million dollars a month and it's doubling every two months.

02
Mechanism

The black market operates through proxy servers that run legitimate accounts and share access across multiple users via a web interface.

Wes explains how the proxy-based system works: sellers run multiple Claude instances on browsers and route user requests through them, but the experience is slow, unreliable, and limited in capacity.

transcript

Wes: What I've understood this to be is these are different instances of the Claude website running. So, they seem to have a bunch of browsers running and they're proxying it through. So, what they are doing here is they are proxying it through. So, they have a whole bunch of Claude instances running on a browser somewhere and they are running all of these different chats and keeping track of the chat IDs that belong to me and their proxy in the middle is they're filtering it out. So, they're using the same one over for multiple people.

explains mechanism · 1provides context · 2

03
Mechanism

The black market ecosystem involves upstream account theft via stolen credit cards and NPM worms, midstream token pooling and reverse engineering, downstream transfer stations providing clean APIs, and end users seeking cheap access.

Matt Lenhard of Vector breaks down the token fraud ecosystem into four layers: upstream actors using stolen credit cards, midstream pooling from various sources including NPM worms, downstream transfer stations providing user-friendly APIs, and the end consumers.

transcript

Matt Lenhard: Upstream you have the credit cards they're maybe using stolen credit cards to be able to register with these big labs, right? Open AI, Anthropic, Gemini, etc. Um and then midstream, this is where they start to pool all of the accounts. And this is kind of the the interesting parts to me. So, they are they're trying to figure out where they can get tokens from absolutely anywhere, right? So, whether that is there's an NPM worm that has scraped your .env file, whether that is reverse engineering some of the things... So, they're trying to reverse engineer all of the APIs and then put it into a single tidy API, which is the next one, the downstream. These are the transfer station.

explains mechanism · 1extends · 1provides context · 1

04
Claim

Black market token sellers make money through three methods: marking up stolen access, swapping models while inflating token counts, and selling usage logs to competitors for model distillation.

The host outlines three ways sellers profit: first by marking up stolen tokens, second by substituting cheaper models while inflating token usage, and third—most importantly—by selling user interaction logs to AI companies for model training through distillation.

transcript

Wes: Meal one is marking up access. We saw that. You you you say here are tokens. I will charge them for you. I stole them so I'm making money on top of that. Meal two, swapping out the models and inflating the tokens. So, we saw that, right? We weren't entirely sure that we were getting real cloud at some point and also inflating the token usage. And then the third one, this is really important, is the logs are the product. So, these LLM companies that are trying to train their own models, what they will often do is called distillation, which is Anthropic has been crying about it for almost six months now, which is essentially you can train your model based on the output of another model. And if you have the logs of the output of somebody actually using Claude code, then you can use those logs to actually train your own model on top of that.

explains mechanism · 1provides context · 1

05
Claim

Buying black market tokens is risky because proxy servers can intercept and modify tool calls to steal data, and the tokens are often stolen from regular users who accidentally leaked their API keys.

The host warns that proxied APIs can intercept tool calls to steal sensitive data, and that purchasing stolen tokens often means taking from regular users who unknowingly leaked their API keys.

transcript

Wes: You have to remember, even if you're running it through a legitimate harness, like Open Code or Claude or Codex, these things are still being proxied. Meaning that they can swap out tool calls, which is maybe if the tool call says, 'Create index.html', they will switch it to create index.html and steal your entire computer contents and all of the IP that's related to your employer, and that would probably end you up in some hot water. As much as you may hate Dario or Sam for what they are doing here, you are often stealing from people that have unknowingly, accidentally leaked their API key. You may be stealing from somebody who has their Cloud Max subscription.

explains mechanism · 1provides context · 3

Highlight slides
Related episodes