Rendered at 06:48:59 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
wtobey1 12 hours ago [-]
I spent years working on financial integrity at a large ads company and this isn't novel at all! The same resale markets are at play for the last generation of internet giant's products. Highly sophisticated actors, able to cobble together impressions through abuse of the billing systems, stolen financial instruments, taken over accounts, etc, create massive markets of discounted impressions for resale. It was very interesting to compete against them as we hardened our defenses and they invented new ways to exploit them. I imagine the same defensive tools and techniques are being deployed by my former colleagues who moved to the labs.
skybrian 9 hours ago [-]
Yes, and I'm reminded of Bitcoin miners relocating for subsidized electricity or even stealing it outright.
weregiraffe 2 hours ago [-]
Do you ever feel shame for working in an ads company? Or is the pay good enough to justify the atrocities you help to perpetrate?
defrost 2 hours ago [-]
and when did you stop beating your wife?
> is the pay good enough to justify the atrocities you help to perpetrate?
Given that the parent comment literally stated that they worked in adtech, this is not "begging the question" in the way that you're implying.
You might disagree with the assertion that adtech is immoral, but that's a difference of opinion, not evidence of a logical fallacy.
weregiraffe 33 minutes ago [-]
Oh, I consider ads-driven economy an atrocity.
defrost 21 minutes ago [-]
Of possible interest, Ballard's The Atrocity Exhibition is themed abut mass media intrusion into private mind spaces, Carey's Bliss about an ad exec whose heart stops, re-awakening convinced he is in hell (but merely life with the scales fallen from his eyes).
Such things are still not reason to dis other HN commentators - there's always reddit for that.
infinite_spin 47 minutes ago [-]
[dead]
namanyayg 14 hours ago [-]
One aspect that seems to be missing is the abuse of the free credits provided for new companies by AWS, Azure, and other providers.
I know of a friend's company in India who purchased inference, at 4% of the actual price and states that it gave him an unbeatable competitive edge in their large running video influence pipelines. Any new competitors could not offer their pricing at all.
Primarily that operated because registering a new company getting free AWS credits was a very tiny cost
mlenhard 13 hours ago [-]
I was going to cover this in a follow-up article, but yeah, there are network of token brokers who buy unused credits from startups and then resell them.
thenthenthen 3 hours ago [-]
Thanks matt for including the Mandarin terms and the great article!
hahahaa 9 hours ago [-]
A bit like setting up a supermarket that just sells another competing supermarket's "free fruit for kids" fruit.
namanyayg 9 hours ago [-]
I should have added that I ran my first startup in India for 8 years before moving to the states, that's why I have an insider view.
juleiie 13 hours ago [-]
Video influence pipelines from India huh?
No wonder social media is so shit nowadays. All that brainwashing and propaganda from third world countries, now at 4% the price!
WheatMillington 5 hours ago [-]
If we're going to insist on continuing to use the offensive language of "third world country", at least apply it correctly. India is not what even the most casual racist would consider "third world".
unmole 4 hours ago [-]
> India is not what even the most casual racist would consider "third world".
I don't follow. India was Third World in the original Cold War sense as a founder and leader of the Non-Aligned Movement, and it still fits the term's colloquial sense through low GDP per-capita, poor HDI figures, weak state capacity, corruption and uneven infrastructure.
The label might be offensive, the comment you responded to most certainly is. But excluding India from the Third World is hard to justify.
4848488448 13 hours ago [-]
the in India wasnt even needed no worries
ac2u 12 hours ago [-]
Some countries have more complexity to registering a new company than others, and perhaps it’s the establishment of a new legal entity that is an unlocker to the free credits.
I don’t know if that’s true of India or not, but I like to give comment authors the benefit of the doubt that being specific about the geography was helpful context here
manquer 10 hours ago [-]
India is very bureaucratic and slow for starting a new business new entity. It ranked 63rd on the most recent world bank survey of 2020[1], and it is even more painful to close one.
So that report was discontinued after relatively proven statistical gaming and interference by several countries, doesn’t exist post 2020.
Post 2020 SPICE+ launched making registration trivially fast. However really the trick isn’t creating and closing companies, it’s that the fact majority of reporting that would catch scam companies like these just get ignored and gather small civil penalties payable years later or not at all, while keeping up with major reporting that might close their bank accounts… it’s a very disorganised system that facilitates a lot of unpleasant activity.
inigyou 9 hours ago [-]
What's the scam? Generally a country's governance system wouldn't get involved in a dispute this trivial between a foreign company and an individual.
manquer 8 hours ago [-]
The world bank is best quality source I could find, if you know a better source or any fact contradicting the claim India is high friction for general ease of business, that would be welcome.
cumshitpiss 12 hours ago [-]
[dead]
benlivengood 14 hours ago [-]
The real problem is subscription models. Businesses want recurring revenue so they try to game the ratio of fixed subscription prices to COGS but it's always a game and so whoever can figure out the upside for the company can figure out the complementary upside for themselves.
How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
Fixed cost per token simply works.
Aurornis 11 hours ago [-]
The abuse is factored in to pricing and quota structure.
I have some past experience with subscription plans for a much less interesting product. Abuse is inevitable. As you do your math on the subscription costs you look at the actual usage across all accounts, which includes the abuse.
Cleaning up abuse was still a priority because it meant we could give more service to the real customers. It's a frustrating battle because you actually want to give good service to the real customers, but you also want to let each account do as they please with their susbcription. That latter priority probably fades fast for something like an LLM company when you discover that the abuse has become automated and is scaling up so fast that it's tilting the math toward degrading service for everyone.
> Fixed cost per token simply works.
As a consumer, I benefit greatly from the subscription rates. There's a lot of grumbling about how they should go to fixed token for everyone but I'm over hear happy with the subscription plan offerings while they last.
jwsteigerwalt 9 hours ago [-]
Tokens are becoming a hard commodity. Subscriptions don’t work with hard commodities. Subscriptions work fine where fixed costs/capital investment are massive and service delivery is negligible. Think car washes and Netflix. The marginal cost of adding an additional subscriber to a streaming platform or a monthly car was membership is negligible. While there was substantial capital investment to generate the models, we are learning that the service delivery cost of tokens is real.
miohtama 10 hours ago [-]
There is a reason the Max plan gets only so few Fable tokens per week.
hahahaa 9 hours ago [-]
Subscription models are fine if profitable individually. It then is an automated token allocation.
The problem is loss making subscription as a marketing tool. But if you do loss leaders that be the risk you take.
PunchyHamster 14 hours ago [-]
> How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
reverse the pricing structure; give modest discount once you go over certain amount of tokens, then you are incentivized NOT to start multiple accounts.
require first few transactions to be pre-paid to get around at least some of the card problems.
Of course, that would fuck over subsidized plans, but I don't see any option to keep them if you want to avoid the flood
nfbdhdfbf 12 hours ago [-]
> You can't forbid automation because sub-agents are automation.
Is this some kind of attempt to make the other side look better by making the worst argument you can?
PunchyHamster 10 hours ago [-]
....ask the original poster not me ? I just quoted him
grinich 12 hours ago [-]
This is the problem we've been working on solving with WorkOS Radar. We run it for Cursor and a bunch of other AI companies who have a free trial that gives some free inference to test the product.
It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.
I don't think device fingerprinting is the right approach here.
Client-side detection can always be sidestepped, and you need to intermediate the actual inference to get enough signals to make an accurate prediction. There are hundreds of listings for cursor tokens/credits right now.
We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.
reliabilityguy 5 hours ago [-]
> We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.
Can you elaborate how it works? Specific sequence of tokens acts as a canary?
nikcub 34 minutes ago [-]
sign up for the resellers, insert a random id canary into your requests, trace them back on your server to tie it to an account
find fingerprints / signatures of the accounts being used. ban all of them.
eventually build an ml based system that detects these at signup
reinforce with more data. loop forever, etc.
ifwinterco 11 hours ago [-]
It's the same fundamental problem as "ticket touting" for popular events - if you sell something that's in demand at a price that's far lower than the clearing price of the market, you're creating a juicy arbitrage opportunity that sooner or later somebody is going to try and exploit
miki123211 8 hours ago [-]
Not necessarily.
What OpenAI and Anthropic are selling — a flat-rate subscription with both 5-hour and weekly rate limits — is a bit like an all-you-can-eat buffet.
They expect some customers to generate more in costs than they bring in revenue, just like some people at the all-you-can-eat buffet eat more than they pay for, but by the law of large numbers, the mean cost per customer comes out to something the labs are comfortable with.
What the resellers are doing is undermining the labs' assumptions that every person needs to eat and sleep, and hence won't use every 5-hour window to the fullest. It's the equivalent of buing the all-you-can-eat pass for one person, coming into the restaurant with three of the largest suitcases you can find, and filling them to the brim with food, which you later re-sell at much lower prices. In other words, fraud.
byzantinegene 4 hours ago [-]
fraud that cannot be reliably be prevented, which makes the business model in-question fall into 'questionable' category.
nswizzle31 4 hours ago [-]
This is the same terrible analogy used to justify Anthropic shutting off API access for subscribers. It’s nothing like an all-you-can-eat buffer because, as you mention, there are limits!
We are not buying all we can eat. We are buying 3 plates of food every 5 hours (or whatever) and we should be able to do with that food as we please, without anti-consumer tactics to scam us out of not consuming the LIMITS we paid for.
Weirdly, no buffet subscriptions exist that I know of. That should tell you a bit about the viability of this business model.. it will collapse if we had to pay the real cost.
hahahaa 9 hours ago [-]
Yeah but those tickets are never a loss leader. So it feels different.
This is more like sharing Argentinan $2/m Google Premium subscriptions via a load balancer.
tancop 10 hours ago [-]
the way i see it there are 3 types of resellers. the ones using fake credit cards to rack up costs and then cancel the card are doing actual fraud. then you got mass free trial abuse which is more of a gray area and i would say its still wrong. but if you sign up for a subscription, pay for it and resell your monthly tokens thats not at all unethical, even if its breaking their terms and costing the provider money.
imagine ford starts renting out company cars at a huge discount so they can get people to buy the same model for themselves after they drive it at work. its the exact same car and costs the same amount to make, they just take a loss on it and use by anyone other than employees is banned in the contract.
some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash. is that fraud? it costs ford nothing because they get the same payments either way, they just lose potential profits. they are the ones who decided to set up a loss leader and take the risk of someone "abusing" the system so we dont need to use public resources to defend their strategy. that wastes taxpayer money to protect corporate profits, and it creates moral hazard because ford (anthropic) is not the one paying for enforcement.
9 hours ago [-]
Aurornis 9 hours ago [-]
> some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash. is that fraud?
Most likely, yes.
There's a common fallacy that once you pay someone for a service, you are free to do whatever you want with that service. In the case of the rental car, the contract the company entered into would prohibit reselling the services and limit who can drive them and for what purposes.
Some people see these limitations and scream "Not fair! They paid money, they can do whatever they want!" The misunderstanding is that the price they paid was predicated on the specific use. They got a lower price for the rentals because the provider calculated the expected use case and priced it according to that.
If the small company starts renting out the cars to try to maximize how much they're used, that breaks the financial model. That's why this type of use is forbidden in every basic rental contract.
It's the same reason why you can't rent an apartment building and then turn it into an AirBnB. On a smaller scale, it's why you can't go to an all-you-can-eat buffet and load up on food to carry outside to your 5 hungry friends. This type of pricing is everywhere.
There is a vocal online minority who believe user license agreements shouldn't be enforced and individuals should never be considered accountable for following them, but that doesn't even apply to these resellers. This isn't a lowly individual user trying to get back $10 from their $20 per month plan that was going unused. There's no way to even achieve the scale and discounts without mass, automated fraud. They're doing chargeback fraud or using stolen credit cards.
It's not even a crime where the big corporation is the only victim. The higher the volume of fraud on the subscription accounts, the less real usage you and I get for our dollar. These people are jumping on the accounts targeted to individuals like us and abusing them to sell tokens to big corporations trying to abuse them at scale. People like you and I lose when these accounts get their limits reduced or the companies start introducing ID checks and KYC just to use basic services.
inigyou 9 hours ago [-]
Breach of contract isn't fraud though
Aurornis 8 hours ago [-]
Misrepresenting or concealing important facts that constitute breach of contract is fraud.
In the example above, part of signing the contract is agreeing that your usage of the vehicles doesn’t involve reselling them. Signing that contract with intent to re-rent them is a very clear legal problem.
There are several other layers of problems. When you rent something to someone else, you are representing that you have legal standing to rent it out.
If you rent out someone else’s property after agreeing to a contract that says you cannot rent it out, you are doing some more serious misrepresenting of the key facts and your intent. It could also trigger laws about theft of services depending on the situation.
skybrian 9 hours ago [-]
Not every breach of contract is fraud, but signing a contract when you never intended to fulfill your side of the bargain is. For example, if someone signs a contract with a seller, pays them, and the seller disappears, they were defrauded. Or agreeing not to resell something and then doing it anyway.
kmeisthax 2 hours ago [-]
> There is a vocal online minority who believe user license agreements shouldn't be enforced and individuals should never be considered accountable for following them, but that doesn't even apply to these resellers.
What you're vaguely gesturing at is that "Internet nerd culture" is downstream of both neoliberal politics and vague anti-corporate sentiment in a way that combines to give you a sort of "Fuck You, Got Mine Socialism" - i.e. one where being able to freeload off a corporation is automatically good and anything that stops you from doing so is automatically evil.
If you were terminally online in the 1980s, you likely remember phreaking - i.e. that funny little box you built that let you scam AT&T out of long distance phone calls at local rates. Later on in the 90s was the Telecom Act, which more or less institutionalized freeloading off of AT&T infrastructure in the name of antitrust and competition[0]. A few years later, we'd get MP3 and file-sharing services that would do to music labels what Cap'n Crunch whistles did to the phone company. And then BitTorrent would do the same thing to oversubscribed cable Internet services that were very much not designed to serve as distributed edge CDNs for other people's content.
Just to be clear, both AT&T and the music labels deserved it, and it's Comcast's fault for not building fiber infrastructure that would actually meet demand. We did not fight those battles for nothing. But it also established a pattern: any company that engages in marketing fictions in order to offer a more palatable price is really just lying about the costs, and it is the Internet's solemn duty to invent a scheme to maximally abuse those services. Fuck your business model, and we should get paid for fucking your business model, even if fucking it will collapse the house we live in.
[0] Apple fans: just imagine AT&T is the iOS App Store and Epic Games is MCI, and then make all your annoying comments about how Apple "deserves to be paid" or whatever, and you'll get it. Just try not to think too hard about how many phreaking kits Steve Jobs sold...
hahahaa 9 hours ago [-]
Selling your sub tokens is against ToS and somewhat like sharing your gym pass.
10 hours ago [-]
AussieWog93 8 hours ago [-]
>some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash.
I mean, in a more accurate analogy, Ford would be paying for the petrol too.
Inference is expensive and Anthropic did not agree to provide inference to some random third party so that the subscriber can make a few extra bucks.
miohtama 10 hours ago [-]
Instead of credit card, prepaid stablecoin purchases would solve the problem. No chargebacks.
How do the users know they're getting what they're paying for?
I disabled automatic downgrading/rerouting because it sometimes takes me a second to tell when the answer came from a different model than I wanted. You could easily sell Opus as Fable for a good while.
gruez 11 hours ago [-]
You can't, it's all reputation based. Similar to whether drug users don't really know what they got were diluted or not.
inigyou 9 hours ago [-]
At most big festivals there is free drug testing by harm reduction charities. Not that they'll test you for drugs, but they'll test your drugs to make sure they are what you think they are.
At Fusion Festival, I saw a big bulletin board completely covered in notices of "we tested this pill, here's a photo, here's what they thought was in it, here's what was actually in it"
They also spelled the name of the charity wrong on all the maps, so that's nice.
TurdF3rguson 9 hours ago [-]
I think the drug users will know before the Opus users.
byzantinegene 4 hours ago [-]
i doubt the users really care as long as they get the job done, AI in 90% of use cases is just a race to the bottom, nobody cares as long as it's cheap and gets the job done.
edg5000 2 hours ago [-]
If we compare OpenAI subscription prices vs. the cheapest inference providers on OpenRouter, than OpenAI must be losing money. Add the fraud to this and the question is what the future will hold. The only salvation is hardware getting 10x cheaper before the labs run out of money. Otherwise, we'll lose affordable access to bulk tokens.
robluxus 15 hours ago [-]
> For example, one operator’s price-comparison site listed a package that bought the equivalent of $3,333 worth of official Anthropic credit for 425 RMB — roughly $0.13 of usage per $1 spent.
Do these numbers make sense? $0.13 usage per $1 spent?
zaltekk 15 hours ago [-]
I think this was very poorly worded. I believe they’re trying to say you pay the reseller $0.13 to get what costs $1 at the upstream provider.
mmoskal 14 hours ago [-]
Also 425 RMB is about $59 so $1 of tokens for $0.017 not $0.13 (the discount rate quoted also seems off).
kristjansson 13 hours ago [-]
seems like they missed a zero somewhere. its a dollar of usage for a penny and change.
mlenhard 15 hours ago [-]
Yeah, I should probably clean this up. The sentence is a bit hard to understand. What I was trying to show was the steep discounts offered by resellers.
jagged-chisel 15 hours ago [-]
So $1 of usage for $0.13?
SyneRyder 12 hours ago [-]
That sounds entirely plausible. When I was on the Claude Max $100 plan, I would often get the equivalent of at least $1300 API usage, according to the costs counter in Claude Code. That would be about $1 of usage for every $0.075c.
At $1 of usage for $0.13, the reseller is making a tidy profit on top of whatever subscriptions they're reselling.
latchkey 15 hours ago [-]
If you are using a stolen credit card to buy tokens and resell them, then the cost per token is the amount the credit card cost you (and building/running the proxy service), not the value of the tokens themselves.
Ah I was wondering how a certain chinese site I came across did this and it could be this.
That site offers substantial free tokens, is often reported as being flaky and their affiliate links are popping up on different social medias but look sketchy as anything.
chrismarlow9 9 hours ago [-]
This is more concerning to me from the perspective of being able to appear as "multiple entities" to the frontier models. My question is do the companies know and are able to detect and consolidate all these accounts as a single actor and just don't care to combat it? Or are they unable to detect this? And if they are unable to detect it wouldn't it be pretty trivial to use this to influence the model overall? I would think there's more money in using it that way.
1337h4xx 8 hours ago [-]
Don't the operators store the agent traces and resell them as training data to AI companies? Why wasn't this mentioned? Did you find any evidence of that?
bg24 14 hours ago [-]
Nice research and structuring into 4-tier layer. For providers like Anthropic and OpenAI, subscription is the entry point for all these, right? Besides the measures proposed in the article, can token usage % determine these clusters of accounts?
jfim 13 hours ago [-]
There are probably various metrics like language used to prompt the model, number of hours per day spent prompting, and many others.
There are quite a few other mitigations that could be done by providers that aren't mentioned in the article.
lmf4lol 14 hours ago [-]
thats one of the reasons why we vest any of our new customers. We need to know you before you are allowed to use our agent system. When you have an open sign up with some free credits, all hell breaks loose.
cobzilla 12 hours ago [-]
This article is about the mechanics, but the title implies this is unethical. Why is this practice considered unethical?
faeyanpiraat 9 hours ago [-]
Is it ethical?
rustyhancock 12 hours ago [-]
Aren't these figures the wrong way around
"$0.13 of usage per $1 spent"
So I spend a dollar and I get 13 cents worth of usage?
I guess it means the otherway around but I'm not seeing how that phrasing works. Are they paying a premium to access US models?
hsienchuc 14 hours ago [-]
I use both of subscription and API services. on last month, i chat with CLI and let it to do something. After that, maybe in one days pass, i received the $32 USD bill. it cause my left my API key and CLI call the API to do job not through subscription.
3eb7988a1663 10 hours ago [-]
How do you know the reseller is even giving you the genuine article? Could they be advertising Fable but repacking Deepseek?
hn8726 9 hours ago [-]
About the same way you'd know Anthropic is getting you the model you picked. Which to me is not really obvious, given clear differences in quality throughout the day and month
boznz 10 hours ago [-]
The relays sound also like a nice source of monitoring for whoever controls them.
faeyanpiraat 9 hours ago [-]
Its so much stuff going through them, how would they monitor it all?
ericpauley 8 hours ago [-]
AI is big in GPU terms but in raw bytes the whole token economy is laughably tractable.
Case in point: OpenRouter is serving 60T tokens a week, but this is all human text and code (and cache hits!), which is almost certainly compressible enough that you could fit the whole week’s usage on a single hard drive.
Havoc 9 hours ago [-]
How do the distillation buyers know it's real? Heard that these sort of markets are fond of silently substituting inferior models. i.e. sonnet instead of opus etc.
Not unlike narcotics being cut with filler
iririririr 11 hours ago [-]
wow. Ai providers can't solve fraud 101 with their oh-so-dangerous-if-released-models?
i think this alone is the biggest bear signal
inigyou 9 hours ago [-]
How do we define "fraud" if taking a new user discount over and over is fraud?
mito88 13 hours ago [-]
what tokens are these being sold?
feverzsj 14 hours ago [-]
Token is the new cryptocurrency.
arkhiver 14 hours ago [-]
token is the new... token!
inigyou 13 hours ago [-]
You are shadowbanned.
13 hours ago [-]
altmanaltman 14 hours ago [-]
"Token reseller market" is a fancy way of saying credit card fraud. If someone stole xboxs from stores using stolen credit cards and then sold them at 10% of their price, at what point is it a "resller market" and not "criminal enterpirse"?
jonfromsf 12 hours ago [-]
These aren't stolen credit cards. This hack works by maxing out subscription limits of the Anthropic/OpenAI plans, so you never pay additional API fees. It's fraud but not theft.
peyton 11 hours ago [-]
It’s pretty clearly theft of services as generally defined in most places. It’s a hack in the same sense that rolling back your electric meter is a hack.
miohtama 9 hours ago [-]
Violation of Terms of Service is civil, not criminal, matter.
__MatrixMan__ 14 hours ago [-]
With theft, somebody ends up without an Xbox. Theft is wrong. This is mere breach of contract, whether it's wrong depends on the contract.
selectodude 13 hours ago [-]
You’ll have to clarify who the counterparties are to this contract and where the person whose credit card was stolen fits into it.
__MatrixMan__ 12 hours ago [-]
I don't doubt that stolen cards are involved, but you could say that for anything that has to do with card-not-present transactions, e.g. Amazon retail. Is there reason to believe that it's especially prominent in this case?
I assume most of it is just people who want cheaper access to these models and don't mind subsidizing access via somebody who is simultaneously distilling the model.
raincole 4 hours ago [-]
In your world model, hardware and electricity are made out of thin air?
mynegation 12 hours ago [-]
What?! It is definitely credit card fraud, and a criminal enterprise, and by any definition it is wrong. I cannot imagine a jurisdiction where this is a “mere breach of contract”.
__MatrixMan__ 12 hours ago [-]
Where are you getting the idea that the cards are stolen? Sure it's mentioned that some of them likely are, but there's no reason to believe that that's most of them or that the fact that they're stolen has anything to do with the way this market functions.
This is about controlling who gets to use the tokens for what, not about payment fraud.
10 hours ago [-]
zht 13 hours ago [-]
What?
phildenhoff 13 hours ago [-]
It's not _theft_ because nothing is _stolen_. The tokens are being used in a way that breaches the contract agreed to by whomever set up the account with OpenAI, Anthropic, Kilo, Antigravity etc. but it's not theft.
__MatrixMan__ 12 hours ago [-]
Right, theft requires that there be somebody who no longer has access. This is about too many people having access. Piracy might be a more fitting term.
chasd00 12 hours ago [-]
The credit card and the money is what was stolen.
__MatrixMan__ 12 hours ago [-]
Are we reading the same article? That's mentioned once, as a potential alternative, nested in a bulleted list of alternatives. This is not an article about credit card fraud.
This is about people circumventing the model company's attempts to protect their intellectual "property" (which, if you insist on that incoherent usage of the word "property", they themselves stole from the rest of us).
It's equivalent to buying a DVD in the US which is region-locked to Asia. Grey market, not black market. If you use a stolen credit card to buy that DVD, well tat's a totally separate matter.
1337h4xx 7 hours ago [-]
It's mostly refunding and card fraud because "bad money drives out good" in any marketplace. It's equivalent to getting a refund on an Amazon package you received, which is why a frontier model is being sold at around 2% of the face value.
iansmith_hn 14 hours ago [-]
Fair enough. Is the right enforcement then to ignore the "token resellers" and go after the credit card business listed at the "upstream" on his post?
glerk 10 hours ago [-]
one man's fraud is another man's arbitrage opportunity
TokenLat 1 hours ago [-]
[flagged]
receptopalak 13 hours ago [-]
[flagged]
chhxdjsj 5 hours ago [-]
The chinese AI and greymarket peptides scenes feel so vital, fun and wild-west. Imagine spending your life being beholden to USA corporations and being scolded on HN for violating a trillion dollar company’s ToS.
weregiraffe 34 minutes ago [-]
Imagine having all your data stolen, and then getting a new and exciting autoimmune disease.
markus_zhang 14 hours ago [-]
I don't know anything about tokens. Does the following argument make sense?
1. Tokens are model-specific: e.g. tokens used by Anthropic cannot be used in models of other companies.
2. Tokens are generated by GPU cards. They measure the power of GPU cards.
3. Tokens cannot be separated from the models. You sort of "connect" the software part (models) into the hardware part (GPU cards) to use the tokens generated from the hardware.
capitalsigma 14 hours ago [-]
Tokens measure "how much work the model did" in the same way that step counts measure "how far the person went"
GPUs "generate tokens" in the same sense that human feet "generate steps"
You can't compare token counts across different providers to get an absolute measure of "total work done" for the same reason that you can't compare step counts across different people to get an absolute measure of "total distance traveled"
irishcoffee 14 hours ago [-]
No, all 3 points are incorrect. I’m not even pro-LLM and I’ll tell you this.
You should do a bit of reading on what a token is. The short answer is that it’s a series of 2-4 bytes of information turned into an integer.
Your comparisons are akin to asking “are amazon gift cards the same as a bunch of pesos?”
> is the pay good enough to justify the atrocities you help to perpetrate?
C'mon, not every ad jockey is flogging fossil fuels, and even some that do repent: https://www.youtube.com/watch?v=jcrekESgFQI
* https://en.wikipedia.org/wiki/Peter_Carey_(novelist)
You might disagree with the assertion that adtech is immoral, but that's a difference of opinion, not evidence of a logical fallacy.
Such things are still not reason to dis other HN commentators - there's always reddit for that.
I know of a friend's company in India who purchased inference, at 4% of the actual price and states that it gave him an unbeatable competitive edge in their large running video influence pipelines. Any new competitors could not offer their pricing at all.
Primarily that operated because registering a new company getting free AWS credits was a very tiny cost
No wonder social media is so shit nowadays. All that brainwashing and propaganda from third world countries, now at 4% the price!
I don't follow. India was Third World in the original Cold War sense as a founder and leader of the Non-Aligned Movement, and it still fits the term's colloquial sense through low GDP per-capita, poor HDI figures, weak state capacity, corruption and uneven infrastructure.
The label might be offensive, the comment you responded to most certainly is. But excluding India from the Third World is hard to justify.
I don’t know if that’s true of India or not, but I like to give comment authors the benefit of the doubt that being specific about the geography was helpful context here
[1 ]https://openknowledge.worldbank.org/entities/publication/130...
How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
Fixed cost per token simply works.
I have some past experience with subscription plans for a much less interesting product. Abuse is inevitable. As you do your math on the subscription costs you look at the actual usage across all accounts, which includes the abuse.
Cleaning up abuse was still a priority because it meant we could give more service to the real customers. It's a frustrating battle because you actually want to give good service to the real customers, but you also want to let each account do as they please with their susbcription. That latter priority probably fades fast for something like an LLM company when you discover that the abuse has become automated and is scaling up so fast that it's tilting the math toward degrading service for everyone.
> Fixed cost per token simply works.
As a consumer, I benefit greatly from the subscription rates. There's a lot of grumbling about how they should go to fixed token for everyone but I'm over hear happy with the subscription plan offerings while they last.
The problem is loss making subscription as a marketing tool. But if you do loss leaders that be the risk you take.
reverse the pricing structure; give modest discount once you go over certain amount of tokens, then you are incentivized NOT to start multiple accounts.
require first few transactions to be pre-paid to get around at least some of the card problems.
Of course, that would fuck over subsidized plans, but I don't see any option to keep them if you want to avoid the flood
Is this some kind of attempt to make the other side look better by making the worst argument you can?
It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.
https://workos.com/radar
(If you'd like to work on this, we are hiring :))
Client-side detection can always be sidestepped, and you need to intermediate the actual inference to get enough signals to make an accurate prediction. There are hundreds of listings for cursor tokens/credits right now.
We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.
Can you elaborate how it works? Specific sequence of tokens acts as a canary?
find fingerprints / signatures of the accounts being used. ban all of them.
eventually build an ml based system that detects these at signup
reinforce with more data. loop forever, etc.
What OpenAI and Anthropic are selling — a flat-rate subscription with both 5-hour and weekly rate limits — is a bit like an all-you-can-eat buffet.
They expect some customers to generate more in costs than they bring in revenue, just like some people at the all-you-can-eat buffet eat more than they pay for, but by the law of large numbers, the mean cost per customer comes out to something the labs are comfortable with.
What the resellers are doing is undermining the labs' assumptions that every person needs to eat and sleep, and hence won't use every 5-hour window to the fullest. It's the equivalent of buing the all-you-can-eat pass for one person, coming into the restaurant with three of the largest suitcases you can find, and filling them to the brim with food, which you later re-sell at much lower prices. In other words, fraud.
We are not buying all we can eat. We are buying 3 plates of food every 5 hours (or whatever) and we should be able to do with that food as we please, without anti-consumer tactics to scam us out of not consuming the LIMITS we paid for.
Weirdly, no buffet subscriptions exist that I know of. That should tell you a bit about the viability of this business model.. it will collapse if we had to pay the real cost.
This is more like sharing Argentinan $2/m Google Premium subscriptions via a load balancer.
imagine ford starts renting out company cars at a huge discount so they can get people to buy the same model for themselves after they drive it at work. its the exact same car and costs the same amount to make, they just take a loss on it and use by anyone other than employees is banned in the contract.
some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash. is that fraud? it costs ford nothing because they get the same payments either way, they just lose potential profits. they are the ones who decided to set up a loss leader and take the risk of someone "abusing" the system so we dont need to use public resources to defend their strategy. that wastes taxpayer money to protect corporate profits, and it creates moral hazard because ford (anthropic) is not the one paying for enforcement.
Most likely, yes.
There's a common fallacy that once you pay someone for a service, you are free to do whatever you want with that service. In the case of the rental car, the contract the company entered into would prohibit reselling the services and limit who can drive them and for what purposes.
Some people see these limitations and scream "Not fair! They paid money, they can do whatever they want!" The misunderstanding is that the price they paid was predicated on the specific use. They got a lower price for the rentals because the provider calculated the expected use case and priced it according to that.
If the small company starts renting out the cars to try to maximize how much they're used, that breaks the financial model. That's why this type of use is forbidden in every basic rental contract.
It's the same reason why you can't rent an apartment building and then turn it into an AirBnB. On a smaller scale, it's why you can't go to an all-you-can-eat buffet and load up on food to carry outside to your 5 hungry friends. This type of pricing is everywhere.
There is a vocal online minority who believe user license agreements shouldn't be enforced and individuals should never be considered accountable for following them, but that doesn't even apply to these resellers. This isn't a lowly individual user trying to get back $10 from their $20 per month plan that was going unused. There's no way to even achieve the scale and discounts without mass, automated fraud. They're doing chargeback fraud or using stolen credit cards.
It's not even a crime where the big corporation is the only victim. The higher the volume of fraud on the subscription accounts, the less real usage you and I get for our dollar. These people are jumping on the accounts targeted to individuals like us and abusing them to sell tokens to big corporations trying to abuse them at scale. People like you and I lose when these accounts get their limits reduced or the companies start introducing ID checks and KYC just to use basic services.
In the example above, part of signing the contract is agreeing that your usage of the vehicles doesn’t involve reselling them. Signing that contract with intent to re-rent them is a very clear legal problem.
There are several other layers of problems. When you rent something to someone else, you are representing that you have legal standing to rent it out.
If you rent out someone else’s property after agreeing to a contract that says you cannot rent it out, you are doing some more serious misrepresenting of the key facts and your intent. It could also trigger laws about theft of services depending on the situation.
What you're vaguely gesturing at is that "Internet nerd culture" is downstream of both neoliberal politics and vague anti-corporate sentiment in a way that combines to give you a sort of "Fuck You, Got Mine Socialism" - i.e. one where being able to freeload off a corporation is automatically good and anything that stops you from doing so is automatically evil.
If you were terminally online in the 1980s, you likely remember phreaking - i.e. that funny little box you built that let you scam AT&T out of long distance phone calls at local rates. Later on in the 90s was the Telecom Act, which more or less institutionalized freeloading off of AT&T infrastructure in the name of antitrust and competition[0]. A few years later, we'd get MP3 and file-sharing services that would do to music labels what Cap'n Crunch whistles did to the phone company. And then BitTorrent would do the same thing to oversubscribed cable Internet services that were very much not designed to serve as distributed edge CDNs for other people's content.
Just to be clear, both AT&T and the music labels deserved it, and it's Comcast's fault for not building fiber infrastructure that would actually meet demand. We did not fight those battles for nothing. But it also established a pattern: any company that engages in marketing fictions in order to offer a more palatable price is really just lying about the costs, and it is the Internet's solemn duty to invent a scheme to maximally abuse those services. Fuck your business model, and we should get paid for fucking your business model, even if fucking it will collapse the house we live in.
[0] Apple fans: just imagine AT&T is the iOS App Store and Epic Games is MCI, and then make all your annoying comments about how Apple "deserves to be paid" or whatever, and you'll get it. Just try not to think too hard about how many phreaking kits Steve Jobs sold...
I mean, in a more accurate analogy, Ford would be paying for the petrol too.
Inference is expensive and Anthropic did not agree to provide inference to some random third party so that the subscriber can make a few extra bucks.
I disabled automatic downgrading/rerouting because it sometimes takes me a second to tell when the answer came from a different model than I wanted. You could easily sell Opus as Fable for a good while.
At Fusion Festival, I saw a big bulletin board completely covered in notices of "we tested this pill, here's a photo, here's what they thought was in it, here's what was actually in it"
They also spelled the name of the charity wrong on all the maps, so that's nice.
Do these numbers make sense? $0.13 usage per $1 spent?
At $1 of usage for $0.13, the reseller is making a tidy profit on top of whatever subscriptions they're reselling.
Here are the two open source proxies listed in the article: https://github.com/songquanpeng/one-api and https://github.com/QuantumNous/new-api
That site offers substantial free tokens, is often reported as being flaky and their affiliate links are popping up on different social medias but look sketchy as anything.
There are quite a few other mitigations that could be done by providers that aren't mentioned in the article.
"$0.13 of usage per $1 spent"
So I spend a dollar and I get 13 cents worth of usage?
I guess it means the otherway around but I'm not seeing how that phrasing works. Are they paying a premium to access US models?
Case in point: OpenRouter is serving 60T tokens a week, but this is all human text and code (and cache hits!), which is almost certainly compressible enough that you could fit the whole week’s usage on a single hard drive.
Not unlike narcotics being cut with filler
i think this alone is the biggest bear signal
I assume most of it is just people who want cheaper access to these models and don't mind subsidizing access via somebody who is simultaneously distilling the model.
This is about controlling who gets to use the tokens for what, not about payment fraud.
This is about people circumventing the model company's attempts to protect their intellectual "property" (which, if you insist on that incoherent usage of the word "property", they themselves stole from the rest of us).
It's equivalent to buying a DVD in the US which is region-locked to Asia. Grey market, not black market. If you use a stolen credit card to buy that DVD, well tat's a totally separate matter.
1. Tokens are model-specific: e.g. tokens used by Anthropic cannot be used in models of other companies.
2. Tokens are generated by GPU cards. They measure the power of GPU cards.
3. Tokens cannot be separated from the models. You sort of "connect" the software part (models) into the hardware part (GPU cards) to use the tokens generated from the hardware.
GPUs "generate tokens" in the same sense that human feet "generate steps"
You can't compare token counts across different providers to get an absolute measure of "total work done" for the same reason that you can't compare step counts across different people to get an absolute measure of "total distance traveled"
You should do a bit of reading on what a token is. The short answer is that it’s a series of 2-4 bytes of information turned into an integer.
Your comparisons are akin to asking “are amazon gift cards the same as a bunch of pesos?”