An Inside Look at the Relay Market Powering Token Resellers and Fraud
Matt Lenhard's investigation uncovers a market where resellers offer discounted LLM token access by pooling API keys from various sources, predominantly in China. These resellers achieve significant discounts on regular API pricing by abusing free trials, proxying through unprotected support bots, or using stolen credit cards and chargeback attacks. The proxy software they use is open-source, primarily one-api and its more actively developed fork new-api, both legitimate API proxy products that can load-balance requests across a pool of API credentials. Buyers are motivated by cheap tokens, avoiding geo-restrictions, and in some cases collecting data for model distillation. Simon Willison, who links to the investigation, expresses increased caution about exposing his own LLM-driven applications publicly due to fear of abuse leading to large token bills. He notes that the existence of this marketplace means there is now an entire ecosystem that can profit from finding a new unprotected endpoint to exploit. Willison calls for LLM vendors to offer better strict caps for API keys, wanting his apps to stop working the moment they hit a dollar threshold set for a period of time. The investigation's principal source is a Chinese language forum thread.
Developers face increased risk of token theft from a thriving reseller ecosystem exploiting unprotected endpoints.