ATRIUMsearch → argument graph
MechanismVideo · 14:29 — 16:29

The black market token industry is structured as a four-tier pipeline — upstream stolen credit cards, midstream harvested tokens, downstream 'transfer station' proxies, and end users — with models being swapped along the way.

Matthew Lenhard of Vectoral explains how the underground token market works: stolen cards register accounts, tokens are gathered from leaks and trials, unified proxies route requests, and end users buy in. ✦ AI generated

Matthew Lenhard · Syntax · 2026-08-07 · original ↗

starts at this moment · 14:29

Upstream you have the credit cards. They're maybe using stolen credit cards to be able to register with these big labs... And then midstream, this is where they start to pull all of the accounts... whether that is there's an npm worm that has scraped your file, whether that is uh reverse engineering... They're trying to reverse engineer because tokens are tokens and wherever they come from they don't necessarily care. So they're trying to reverse engineer all of the APIs and then put it into a single tidy API which is the next one the downstream. These are the transfer stations... They give you a nice tidy API where you can log in... Then there's me, the end user, looking for a good deal.

verbatim transcript · starts at 14:29

Transcript · around this moment

14:10the CEO and founder of Vectoral, a platform to stop token fraud and abuse that really stems from um problems I ran into at a previous company I was working at where we were constantly battling token fraud and I started to look into it like where is this all stemming from and turns out there's an entire underground market for it. Matt has dove deep into the forums where all these

14:35Chinese sellers are trying to figure it on out and sort of broken it down into four different groups that we have there. Right. Upstream you have the credit cards. They're maybe using stolen credit cards to be able to register with these big labs, right? Open AI, Anthropic, Gemini, etc. Um, and then midstream, this is where they start to pull all of the accounts. And this is kind of the the interesting parts to me.

14:58So they are they're trying to figure out where they can get tokens from absolutely anywhere, right? So whether that is there's an npm worm that has scraped your file, whether that is uh reverse engineering some of the things like I'm sure uh VS Code, Cursor, Kira, all of these places that maybe they offer a trial, maybe they have bought like a $20 plan, but you're able to use

15:24$500 on that single plan because, you know, some of some of these guys are losing money on it. They're trying to reverse engineer because tokens are tokens and wherever they come from they don't necessarily care. So they're trying to reverse engineer all of the APIs and then put it into a single tidy API which is the next one the downstream. These are the transfer stations. So this is what I've been

15:45interacting with right here. They give you a nice tidy API where you can log in. You can see your usage for the day. You can make an API key. They give you a URL that you can ping and it is anthropic compatible. So you can just swap it out in cloud code. This is the transfer station where they take in my request, say create me x, y, and z. And

16:07it's up to them to figure out where those need to be routed. And in our case when I was showing you, it took 8 minutes to do a very simple task. And that's likely because they're always getting shut down and they need to reroute those requests to different APIs to figure out which one will work. And I think that's also why I was running out of tokens much faster than it said. Then

16:29there's me, the end user, looking for a good deal. >> Yeah. So, there's actually uh sites that have popped up now that try to verify this at the different relays or transfer stations because there's a lot of talk of models being swapped out. And so now there's like I guess like verification sites that try to verify this for end users. Like hey are your stolen tokens, you know, actually the model that um

16:52they're purporting to be. >> Now if you're just watching this video saying, "Oh, well I don't know where to steal tokens from." Don't worry. There's an entire website dedicated to reviewing stolen token providers. There's you can go on it and you can say, "I think I need a little bit of fable today." Right? And you can see that LLM API is is pretty good or con.ai has pretty

Around this claim