Stealing and reselling tokens is only one revenue stream: resellers also swap models, inflate token usage, and sell the logs of real Claude usage to Chinese labs for model distillation.
Wes and Matthew explain the three revenue streams of black market operators, highlighting that the captured usage logs become a gold mine for Chinese labs distilling Anthropic or OpenAI models. ✦ AI generated
Wes · Syntax · 2026-08-07 · original ↗
starts at this moment · 18:19
Stealing and selling tokens is not the only way that these guys are making money. This interesting post on China talk, one fish, three meals, where meal one is marking up access... meal 2 swapping out the models and inflating the tokens... And then the third one, this is really important, is the logs are the product. So these LLM companies that are trying to train their own models, what they will often do is called distillation, which is Anthropic has been crying about it for almost 6 months now, which is essentially you can train your model based on the output of another model. And if you have the logs or the output of somebody actually using cloud code, then you can use those logs to actually train your own model... That is an absolute gold mine to these companies that are specifically a lot of them in China that are trying to make their own version of anthropic or open AI models.
verbatim transcript · starts at 18:19
18:06fly under the radar? >> They're pretty clever. Like they're they won't take you for everything you have because they know it gets shut off at that point. And what I've heard, and this was also like uh like my own internal experience, is like you don't really uh notice things until they get really bad. And so, you know, if they're just stealing a few thousand dollars a day from a given API key, it may um
18:30never get noticed. It's only when they start stealing like a hundred thousand or more that for a lot of these large organizations, things start to get flagged. >> Stealing and selling tokens is not the only way that these guys are making money. This interesting post on China talk, one fish, three meals, where meal one is marking up access. We saw that you you you say, "Here are tokens. I
18:49will charge them for you. I stole them, so I'm making money on top of that." meal 2 swapping out the models and inflating the tokens. So, we saw that, right? We weren't entirely sure that we were getting real claude at some point and also inflating the token usage. I we spent uh $2 worth of tokens and then it charged me six. That doesn't make sense. It's 5xing the actual token usage. That
19:14can kind of get you. And then the third one, this is really important, is the logs are the product. So these LLM companies that are trying to train their own models, what they will often do is called distillation, which is Anthropic has been crying about it for almost 6 months now, which is essentially you can train your model based on the output of another model. And if you have the logs
19:38or the output of somebody actually using cloud code, then you can use those logs to actually train your own model. On top of that, the data of people actually using your model and saying yes, this is good. No, that is bad. That is an absolute gold mine to these companies that are specifically a lot of them in China that are trying to make their own version of anthropic or open AI models
20:05and they need this data in order to go. >> So the the the way it works with the Chinese labs is uh say they're trying to distill anthropic, right? They need a way to basically disguise their traffic across a number of different sources. And so they will buy the some of this uh traffic through the account sourcing or the account layer I was talking about earlier as well as the relays
20:30themselves. They do this through a bunch of them basically to reduce like the kind of fingerprint that Anthropic is able to detect. Should you be buying tokens on the dark web from sketchy Chinese website, even if they are seemingly legitimate claude code? Probably not. You have to remember even if you're running it through a legitimate harness like open code or cloud or codeex, these things are still
20:52being proxied, meaning that they can swap out tool calls, which is maybe the tool call says create index.html, they will switch it to create index.html and steal your entire computer contents and all of the IP that's related to your employer. and that would probably end you up in some hot water. These APIs, I've learned, are flaky. They're slow. You're not always sure you're getting what you want, and they are using up way
- ·Stealing tokens is only one of three revenue streams
- ·Meal two: swapping models and inflating token usage
- ·Resellers also sell real usage logs for distillation
- ·Logs of real Claude usage are the product
- ·Distillation trains new models on another's output
- ·A gold mine for Chinese labs building rival models
- ·Anthropic has been flagging this for ~6 months