Buying black market tokens is risky because proxy servers can intercept and modify tool calls to steal data, and the tokens are often stolen from regular users who accidentally leaked their API keys.
The host warns that proxied APIs can intercept tool calls to steal sensitive data, and that purchasing stolen tokens often means taking from regular users who unknowingly leaked their API keys. ✦ AI generated
Wes · Syntax · 2026-08-07 · original ↗
starts at this moment · 20:28
You have to remember, even if you're running it through a legitimate harness, like Open Code or Claude or Codex, these things are still being proxied. Meaning that they can swap out tool calls, which is maybe if the tool call says, 'Create index.html', they will switch it to create index.html and steal your entire computer contents and all of the IP that's related to your employer, and that would probably end you up in some hot water. As much as you may hate Dario or Sam for what they are doing here, you are often stealing from people that have unknowingly, accidentally leaked their API key. You may be stealing from somebody who has their Cloud Max subscription.
verbatim transcript · starts at 20:28
20:28earlier, as well as the relays themselves. They do this through a bunch of them basically to reduce like the kind of fingerprint that Anthropic's able to detect. >> Should you be buying tokens on the dark web from sketchy Chinese website, even if they are seemingly legitimate Claude code? Uh probably not. You have to remember, even if you're running it through a legitimate harness, like Open Code or Claude or Codex,
20:51these things are still being proxied. Meaning that they can swap out tool calls, which is maybe if the tool call says, "Create index.html", they will switch it to create index.html and steal your entire computer contents and all of the IP that's related to your employer, and that would probably end you up in some hot water. These APIs I've learned are flaky, they're slow, you're not always sure you're getting what you
21:13want, and they are using up way more tokens than you probably think they are. As much as you may hate Dario or Sam for what they are doing here, you are often stealing from people that have unknowingly, accidentally leaked their API key. You may be stealing from somebody who has their Cloud Max subscription. You often hear from people who are saying, "I did three prompts and I've used up my entire usage." Well,
21:36maybe your API keys got leaked. You probably should take a look at that. You are much better off spending your money on a bit more of an open stack, even if those models of are the Chinese variety. I got no problem with that, right? So, go to somewhere like OpenRouter and take a look at all the different models that they have available, and a lot of these
21:54are significantly cheaper for almost as good of. They're not as good, but almost as good. And if you're just building a CRUD app, you don't need the some of these best models out there. You're going to get a lot more value out of that. Switch to a harness that is a bit more open that allows you to switch between all the different models. So, what I mean by that is go grab OpenCode
22:17or Py, or any of these other harnesses that will allow you to switch between different models and different providers. I think that's a much better deal than going on some sketchy website and buying what you think might be legitimate tokens that are probably stolen.