The black market ecosystem involves upstream account theft via stolen credit cards and NPM worms, midstream token pooling and reverse engineering, downstream transfer stations providing clean APIs, and end users seeking cheap access.
Matt Lenhard of Vector breaks down the token fraud ecosystem into four layers: upstream actors using stolen credit cards, midstream pooling from various sources including NPM worms, downstream transfer stations providing user-friendly APIs, and the end consumers. ✦ AI generated
Matt Lenhard · Syntax · 2026-08-07 · original ↗
starts at this moment · 14:28
Upstream you have the credit cards they're maybe using stolen credit cards to be able to register with these big labs, right? Open AI, Anthropic, Gemini, etc. Um and then midstream, this is where they start to pool all of the accounts. And this is kind of the the interesting parts to me. So, they are they're trying to figure out where they can get tokens from absolutely anywhere, right? So, whether that is there's an NPM worm that has scraped your .env file, whether that is reverse engineering some of the things... So, they're trying to reverse engineer all of the APIs and then put it into a single tidy API, which is the next one, the downstream. These are the transfer station.
verbatim transcript · starts at 14:28
14:10CEO and founder of Vector, a platform to stop token fraud and abuse. It really stems from problems I ran into a previous company I was working at where we were constantly battling token fraud. And I started to look into it, like where is this all stemming from? It turns out there's an entire underground market for it. >> Matt has dove deep into the forums where all these Chinese sellers are trying to
14:37figure it on out and sort of broken it down into four different groups that we have there, right? Upstream you have the credit cards they're maybe using stolen credit cards to be able to register with these big labs, right? Open AI, Anthropic, Gemini, etc. Um and then midstream, this is where they start to pool all of the accounts. And this is kind of the the interesting parts to me.
14:58So, they are they're trying to figure out where they can get tokens from absolutely anywhere, right? So, whether that is there's an NPM worm that has scraped your .env file, whether that is reverse engineering some of the things, like I'm sure VS Code, Cursor, Kiro, all of these places that maybe they offer a a maybe they have bought like a $20 plan, but you're able to use $500 on that single
15:26plan because you know some some of these guys are losing money on it. They're trying to reverse engineer cuz tokens are tokens, and wherever they come from, they don't necessarily care. So, they're trying to reverse engineer all of the APIs and then put it into a single tidy API, which is the next one, the downstream. These are the transfer station. So, this is what I've been interacting with right here. They give
15:47you a nice tidy API where you can log in, you can see your usage for the day, you can make an API key, they give you a URL that you can ping, and it is Anthropic compatible, so you can just swap it out in cloud code. This is the transfer station where they take in my request, they create me X, Y, and Z, and it's up to them to figure out where
16:09those need to be routed. And in our case, when I was showing you, it took 8 minutes to do a very simple task, and that's likely because they're always getting shut down, and they need to reroute those requests to different APIs to figure out which one will work. And I think that's also why I was running out of tokens much faster than it said. Then there's me, the end user, looking
16:31for a good deal. >> Yeah, so there's actually sites that have popped up now that try to verify this at the different relays or transfer stations because there's a lot of talk of models being swapped out. And so now there's like I guess like verification sites that try to verify this for end users. Like, "Hey, are your stolen tokens, you know, actually the model that they're purporting to be?"