LLM Token Reselling Market Exploits API Key Abuse
Matt Lenhard's investigation reveals a thriving market in China for reselling LLM tokens at discounted rates. Resellers pool API credentials from various sources, abusing free trials, unprotected support bots, stolen credit cards, and chargeback attacks. They use open-source proxy software like one-api and its fork new-api to load-balance requests across pooled credentials. Buyers seek cheap tokens, bypass geo-restrictions, or collect data for model distillation. The ecosystem profits from finding unprotected endpoints, raising concerns about token abuse and the need for stricter API usage caps. Simon Willison highlighted the issue on his blog, linking to a Chinese forum thread as the principal source.
Key facts
- Investigation by Matt Lenhard
- Market primarily in China
- Resellers offer discounts on LLM tokens
- Abuses include free trials, stolen credit cards, chargeback attacks
- Uses open-source proxies: one-api and new-api
- Buyers seek cheap tokens, avoid geo-restrictions, or distill models
- Ecosystem profits from unprotected endpoints
- Simon Willison posted on 26th July 2026
Entities
Institutions
- Simon Willison
Locations
- China