The relay market powering token resellers and fraud
Posted by mlenhard 1 day ago
Comments
Comment by wtobey1 1 day ago
Comment by skybrian 23 hours ago
Comment by namanyayg 1 day ago
I know of a friend's company in India who purchased inference, at 4% of the actual price and states that it gave him an unbeatable competitive edge in their large running video influence pipelines. Any new competitors could not offer their pricing at all.
Primarily that operated because registering a new company getting free AWS credits was a very tiny cost
Comment by mlenhard 1 day ago
Comment by thenthenthen 17 hours ago
Comment by hahahaa 23 hours ago
Comment by namanyayg 23 hours ago
Comment by juleiie 1 day ago
No wonder social media is so shit nowadays. All that brainwashing and propaganda from third world countries, now at 4% the price!
Comment by WheatMillington 19 hours ago
Comment by unmole 19 hours ago
I don't follow. India was Third World in the original Cold War sense as a founder and leader of the Non-Aligned Movement, and it still fits the term's colloquial sense through low GDP per-capita, poor HDI figures, weak state capacity, corruption and uneven infrastructure.
The label might be offensive, the comment you responded to most certainly is. But excluding India from the Third World is hard to justify.
Comment by 4848488448 1 day ago
Comment by ac2u 1 day ago
I don’t know if that’s true of India or not, but I like to give comment authors the benefit of the doubt that being specific about the geography was helpful context here
Comment by manquer 1 day ago
[1 ]https://openknowledge.worldbank.org/entities/publication/130...
Comment by cannonpr 1 day ago
Comment by inigyou 23 hours ago
Comment by cannonpr 10 hours ago
Comment by Ekaros 11 hours ago
Comment by manquer 22 hours ago
Comment by cannonpr 10 hours ago
Comment by cumshitpiss 1 day ago
Comment by benlivengood 1 day ago
How would one even word a bulletproof subscription contract for agentic tokens, anyway? You can't forbid automation because sub-agents are automation. You could forbid "using tokens for the benefit of more than the human who signed up" but then what do families (especially with kids) need to do? What if your friend asks you a question and you turn to a chat model? Forbidding "reselling" tokens outside of a household sounds like the closest terms but that's leaky for anyone who travels a lot, etc.
Fixed cost per token simply works.
Comment by Aurornis 1 day ago
I have some past experience with subscription plans for a much less interesting product. Abuse is inevitable. As you do your math on the subscription costs you look at the actual usage across all accounts, which includes the abuse.
Cleaning up abuse was still a priority because it meant we could give more service to the real customers. It's a frustrating battle because you actually want to give good service to the real customers, but you also want to let each account do as they please with their susbcription. That latter priority probably fades fast for something like an LLM company when you discover that the abuse has become automated and is scaling up so fast that it's tilting the math toward degrading service for everyone.
> Fixed cost per token simply works.
As a consumer, I benefit greatly from the subscription rates. There's a lot of grumbling about how they should go to fixed token for everyone but I'm over hear happy with the subscription plan offerings while they last.
Comment by jwsteigerwalt 1 day ago
Comment by miohtama 1 day ago
Comment by hahahaa 23 hours ago
The problem is loss making subscription as a marketing tool. But if you do loss leaders that be the risk you take.
Comment by PunchyHamster 1 day ago
reverse the pricing structure; give modest discount once you go over certain amount of tokens, then you are incentivized NOT to start multiple accounts.
require first few transactions to be pre-paid to get around at least some of the card problems.
Of course, that would fuck over subsidized plans, but I don't see any option to keep them if you want to avoid the flood
Comment by nfbdhdfbf 1 day ago
Is this some kind of attempt to make the other side look better by making the worst argument you can?
Comment by PunchyHamster 1 day ago
Comment by ifwinterco 1 day ago
Comment by miki123211 22 hours ago
What OpenAI and Anthropic are selling — a flat-rate subscription with both 5-hour and weekly rate limits — is a bit like an all-you-can-eat buffet.
They expect some customers to generate more in costs than they bring in revenue, just like some people at the all-you-can-eat buffet eat more than they pay for, but by the law of large numbers, the mean cost per customer comes out to something the labs are comfortable with.
What the resellers are doing is undermining the labs' assumptions that every person needs to eat and sleep, and hence won't use every 5-hour window to the fullest. It's the equivalent of buing the all-you-can-eat pass for one person, coming into the restaurant with three of the largest suitcases you can find, and filling them to the brim with food, which you later re-sell at much lower prices. In other words, fraud.
Comment by nswizzle31 18 hours ago
We are not buying all we can eat. We are buying 3 plates of food every 5 hours (or whatever) and we should be able to do with that food as we please, without anti-consumer tactics to scam us out of not consuming the LIMITS we paid for.
Weirdly, no buffet subscriptions exist that I know of. That should tell you a bit about the viability of this business model.. it will collapse if we had to pay the real cost.
Comment by ifwinterco 14 hours ago
Incredibly obvious solution to this problem: become a middleman who buys spare tokens from people who don't need them but can buy them for 10c, and sell them to the people who get charged a full dollar.
Spread is huge, so you can make a very nice profit for yourself and still make it very worthwhile for the other two parties
Comment by byzantinegene 19 hours ago
Comment by hahahaa 23 hours ago
This is more like sharing Argentinan $2/m Google Premium subscriptions via a load balancer.
Comment by tancop 1 day ago
imagine ford starts renting out company cars at a huge discount so they can get people to buy the same model for themselves after they drive it at work. its the exact same car and costs the same amount to make, they just take a loss on it and use by anyone other than employees is banned in the contract.
some small company realizes they dont really use their cars that much so they rent them out again for 3 days a week to get some extra cash. is that fraud? it costs ford nothing because they get the same payments either way, they just lose potential profits. they are the ones who decided to set up a loss leader and take the risk of someone "abusing" the system so we dont need to use public resources to defend their strategy. that wastes taxpayer money to protect corporate profits, and it creates moral hazard because ford (anthropic) is not the one paying for enforcement.
Comment by Aurornis 1 day ago
Most likely, yes.
There's a common fallacy that once you pay someone for a service, you are free to do whatever you want with that service. In the case of the rental car, the contract the company entered into would prohibit reselling the services and limit who can drive them and for what purposes.
Some people see these limitations and scream "Not fair! They paid money, they can do whatever they want!" The misunderstanding is that the price they paid was predicated on the specific use. They got a lower price for the rentals because the provider calculated the expected use case and priced it according to that.
If the small company starts renting out the cars to try to maximize how much they're used, that breaks the financial model. That's why this type of use is forbidden in every basic rental contract.
It's the same reason why you can't rent an apartment building and then turn it into an AirBnB. On a smaller scale, it's why you can't go to an all-you-can-eat buffet and load up on food to carry outside to your 5 hungry friends. This type of pricing is everywhere.
There is a vocal online minority who believe user license agreements shouldn't be enforced and individuals should never be considered accountable for following them, but that doesn't even apply to these resellers. This isn't a lowly individual user trying to get back $10 from their $20 per month plan that was going unused. There's no way to even achieve the scale and discounts without mass, automated fraud. They're doing chargeback fraud or using stolen credit cards.
It's not even a crime where the big corporation is the only victim. The higher the volume of fraud on the subscription accounts, the less real usage you and I get for our dollar. These people are jumping on the accounts targeted to individuals like us and abusing them to sell tokens to big corporations trying to abuse them at scale. People like you and I lose when these accounts get their limits reduced or the companies start introducing ID checks and KYC just to use basic services.
Comment by inigyou 23 hours ago
Comment by Aurornis 23 hours ago
In the example above, part of signing the contract is agreeing that your usage of the vehicles doesn’t involve reselling them. Signing that contract with intent to re-rent them is a very clear legal problem.
There are several other layers of problems. When you rent something to someone else, you are representing that you have legal standing to rent it out.
If you rent out someone else’s property after agreeing to a contract that says you cannot rent it out, you are doing some more serious misrepresenting of the key facts and your intent. It could also trigger laws about theft of services depending on the situation.
Comment by skybrian 23 hours ago
Comment by kmeisthax 16 hours ago
What you're vaguely gesturing at is that "Internet nerd culture" is downstream of both neoliberal politics and vague anti-corporate sentiment in a way that combines to give you a sort of "Fuck You, Got Mine Socialism" - i.e. one where being able to freeload off a corporation is automatically good and anything that stops you from doing so is automatically evil.
If you were terminally online in the 1980s, you likely remember phreaking - i.e. that funny little box you built that let you scam AT&T out of long distance phone calls at local rates. Later on in the 90s was the Telecom Act, which more or less institutionalized freeloading off of AT&T infrastructure in the name of antitrust and competition[0]. A few years later, we'd get MP3 and file-sharing services that would do to music labels what Cap'n Crunch whistles did to the phone company. And then BitTorrent would do the same thing to oversubscribed cable Internet services that were very much not designed to serve as distributed edge CDNs for other people's content.
Just to be clear, both AT&T and the music labels deserved it, and it's Comcast's fault for not building fiber infrastructure that would actually meet demand. We did not fight those battles for nothing. But it also established a pattern: any company that engages in marketing fictions in order to offer a more palatable price is really just lying about the costs, and it is the Internet's solemn duty to invent a scheme to maximally abuse those services. Fuck your business model, and we should get paid for fucking your business model, even if fucking it will collapse the house we live in.
[0] Apple fans: just imagine AT&T is the iOS App Store and Epic Games is MCI, and then make all your annoying comments about how Apple "deserves to be paid" or whatever, and you'll get it. Just try not to think too hard about how many phreaking kits Steve Jobs sold...
Comment by hahahaa 23 hours ago
Comment by AussieWog93 22 hours ago
I mean, in a more accurate analogy, Ford would be paying for the petrol too.
Inference is expensive and Anthropic did not agree to provide inference to some random third party so that the subscriber can make a few extra bucks.
Comment by grinich 1 day ago
It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.
(If you'd like to work on this, we are hiring :))
Comment by mlenhard 1 day ago
Client-side detection can always be sidestepped, and you need to intermediate the actual inference to get enough signals to make an accurate prediction. There are hundreds of listings for cursor tokens/credits right now.
We use canary values to detect the resellers, and I believe that's the only approach that will actually work at scale.
Comment by reliabilityguy 20 hours ago
Can you elaborate how it works? Specific sequence of tokens acts as a canary?
Comment by nikcub 15 hours ago
find fingerprints / signatures of the accounts being used. ban all of them.
eventually build an ml based system that detects these at signup
reinforce with more data. loop forever, etc.
Comment by nojs 1 day ago
Comment by blfr 1 day ago
I disabled automatic downgrading/rerouting because it sometimes takes me a second to tell when the answer came from a different model than I wanted. You could easily sell Opus as Fable for a good while.
Comment by gruez 1 day ago
Comment by inigyou 23 hours ago
At Fusion Festival, I saw a big bulletin board completely covered in notices of "we tested this pill, here's a photo, here's what they thought was in it, here's what was actually in it"
They also spelled the name of the charity wrong on all the maps, so that's nice.
Comment by TurdF3rguson 23 hours ago
Comment by byzantinegene 19 hours ago
Comment by robluxus 1 day ago
Do these numbers make sense? $0.13 usage per $1 spent?
Comment by zaltekk 1 day ago
Comment by mmoskal 1 day ago
Comment by kristjansson 1 day ago
Comment by mlenhard 1 day ago
Comment by jagged-chisel 1 day ago
Comment by SyneRyder 1 day ago
At $1 of usage for $0.13, the reseller is making a tidy profit on top of whatever subscriptions they're reselling.
Comment by latchkey 1 day ago
Comment by simonw 1 day ago
Here are the two open source proxies listed in the article: https://github.com/songquanpeng/one-api and https://github.com/QuantumNous/new-api
Comment by hahahaa 23 hours ago
That site offers substantial free tokens, is often reported as being flaky and their affiliate links are popping up on different social medias but look sketchy as anything.
Comment by edg5000 17 hours ago
Comment by jbstack 3 hours ago
Comment by bg24 1 day ago
Comment by jfim 1 day ago
There are quite a few other mitigations that could be done by providers that aren't mentioned in the article.
Comment by chrismarlow9 23 hours ago
Comment by 1337h4xx 22 hours ago
Comment by lmf4lol 1 day ago
Comment by renezander030 13 hours ago
Comment by hsienchuc 1 day ago
Comment by rustyhancock 1 day ago
"$0.13 of usage per $1 spent"
So I spend a dollar and I get 13 cents worth of usage?
I guess it means the otherway around but I'm not seeing how that phrasing works. Are they paying a premium to access US models?
Comment by 3eb7988a1663 1 day ago
Comment by hn8726 23 hours ago
Comment by boznz 1 day ago
Comment by faeyanpiraat 1 day ago
Comment by ericpauley 22 hours ago
Case in point: OpenRouter is serving 60T tokens a week, but this is all human text and code (and cache hits!), which is almost certainly compressible enough that you could fit the whole week’s usage on a single hard drive.
Comment by Havoc 23 hours ago
Not unlike narcotics being cut with filler
Comment by iririririr 1 day ago
i think this alone is the biggest bear signal
Comment by cobzilla 1 day ago
Comment by chihuahua 10 hours ago
"Why is this practice considered unethical?"
Next week: Shoplifting batteries and laundry detergent, and reselling it on Ebay. "Why is this practice considered unethical?"
Comment by faeyanpiraat 1 day ago
Comment by imp0cat 12 hours ago
Comment by mito88 1 day ago
Comment by feverzsj 1 day ago
Comment by altmanaltman 1 day ago
Comment by jonfromsf 1 day ago
Comment by chihuahua 10 hours ago
Comment by peyton 1 day ago
Comment by miohtama 1 day ago
Comment by jbstack 3 hours ago
For example, if you take out a loan and you sign terms and conditions which say you agree to pay it back and then later your circumstances change and you can't pay, that's probably just a civil matter. But if, at the time you signed the agreement, you had planned to deliberately not pay it back, that's fraud and therefore criminal. The fraud is in the fact that you are making a false representation: you are saying you will pay it back, but you know that to be false. It's a very different thing from believing it to be true, but it then later turns out not to be true.
The same principle applies to LLM subscriptions (or any other contract).
Comment by __MatrixMan__ 1 day ago
Comment by selectodude 1 day ago
Comment by __MatrixMan__ 1 day ago
I assume most of it is just people who want cheaper access to these models and don't mind subsidizing access via somebody who is simultaneously distilling the model.
Comment by raincole 19 hours ago
Comment by mynegation 1 day ago
Comment by __MatrixMan__ 1 day ago
This is about controlling who gets to use the tokens for what, not about payment fraud.
Comment by zht 1 day ago
Comment by phildenhoff 1 day ago
Comment by chasd00 1 day ago
Comment by __MatrixMan__ 1 day ago
This is about people circumventing the model company's attempts to protect their intellectual "property" (which, if you insist on that incoherent usage of the word "property", they themselves stole from the rest of us).
It's equivalent to buying a DVD in the US which is region-locked to Asia. Grey market, not black market. If you use a stolen credit card to buy that DVD, well tat's a totally separate matter.
Comment by 1337h4xx 22 hours ago
Comment by __MatrixMan__ 1 day ago
Comment by iansmith_hn 1 day ago
Comment by glerk 1 day ago
Comment by Sattyamjjain 8 hours ago
Comment by receptopalak 1 day ago
Comment by TokenLat 16 hours ago
Comment by ken_solar 13 hours ago
Comment by weregiraffe 16 hours ago
Comment by tomhow 6 hours ago
We detached this comment from https://news.ycombinator.com/item?id=49060922 and marked it off topic.
Comment by defrost 16 hours ago
> is the pay good enough to justify the atrocities you help to perpetrate?
C'mon, not every ad jockey is flogging fossil fuels, and even some that do repent: https://www.youtube.com/watch?v=jcrekESgFQI
Comment by saghm 15 hours ago
You might disagree with the assertion that adtech is immoral, but that's a difference of opinion, not evidence of a logical fallacy.
Comment by defrost 14 hours ago
Ergo sometimes I opt for not just quoting and linking to
Comment by saghm 6 hours ago
Comment by 21asdffdsa12 13 hours ago
Comment by weregiraffe 15 hours ago
Comment by defrost 15 hours ago
Such things are still not reason to dis other HN commentators - there's always reddit for that.
Comment by datsci_est_2015 14 hours ago
Mmm, this I disagree with particularly. I view HN as a forum dedicated to the technology professions, and as such, it’s an extremely appropriate place to shame those in the profession who refuse to consider the second-order effects of their work.
We (those in the technology profession) have no union through which we can encourage professional standards and ethics and codes of conduct. Shame is pretty much the only and last bastion for those of us who care about how we make our money, and not just the amount written on the paycheck.
I know there are some people, both in this forum, and who I’ve met in person - (“Raytheon? How do you feel about the moral dilemma of working for a weapons manufacturer?” … “We manufacture weapons? I just work in HR.”) - who will never lose an ounce of sleep considering their line of work due to an underdeveloped sense of ethics.
But there are some people who are in the middle ground who can still be won over. Every year that passes it becomes more important that technologists are aware of the ethical implications of their work - no matter how much capital incentivizes the opposite. Don’t let a paycheck delude you.
Comment by defrost 14 hours ago
I'd suggest taking that up with Paul Graham, @dang, and @tomhow - they would respond that curious conversation about second order effects is what they seek - sans the direct personal attacks seeking to directly shame another person for their choices.
> How do you feel about the moral dilemma of working for a weapons manufacturer?
Weapons, of course, cut both ways; Ukraine is pushing back against an aggressor by using weapons, long range sensing, passive radar, etc.
> Every year that passes it becomes more important that technologists are aware of the ethical implications of their work
Agreed - that doesn't imply you should call perceived less enlightened others names or champion throwing them in the stocks .. such things rarely convert and often harden resistance.
Comment by datsci_est_2015 13 hours ago
Humans use shame to correct antisocial behavior, and humans feel shame in order to avoid antisocial behavior. The technology professions are rife with antisocial behavior. Our leaders are chosen and their behavior is optimized as antisocial, for shareholder (and personal) short-term growth.
> Weapons, of course, cut both ways; Ukraine is pushing back against an aggressor by using weapons, long range sensing, passive radar, etc.
This is an entirely different subject that I don’t think we should get sidetracked by. I’ll just recommend Die Physiker (or one of its translations) as a fun starting point for radicalization against the argument you presented.
Comment by defrost 13 hours ago
As a gentle reminder, it was yourself that raised weapons as a moral dilemma, I responded with no argument other than a plain observation.
> but ideally those who are currently earning money from unethical sources should feel ashamed
More often they likely sleep deeply on sheets of insanely high thread count, shame only goes so far to effect change.
> I’ll just recommend Die Physiker
If I recall correctly that came up when I had a long discussion with Mark Oliphant in the late 1970s, William Tutte had a few books of his own to recommend on similar themes not long after.
Comment by datsci_est_2015 13 hours ago
Do you have alternative suggestions, or will you stick to simply discouraging the use of shame on this forum?
Comment by tomhow 6 hours ago
We can critique issues and trends in the industry or broader economy, including advertising; that happens all the time here. But also, on HN we're trying for conversation that is curious and thoughtful, at a standard that is higher than the average discussion forum. If we're going to make sweeping assertions like “advertising shouldn't exist”, we also need to offer suggestions of viable alternatives for ways that companies can get their products known about by people who might need them, and for websites to generate income to fund their operations. These are absolutely valid topics of thoughtful discussion in the spirit of curious conversation, which is entirely what HN is for.
Shaming an individual for working in a domain you've decided you don't like (though legal and widespread) is never okay here.
Comment by defrost 12 hours ago
There are many forums that allow and even encourage attacks on others.
Comment by antonvs 12 hours ago
The HN guidelines follow the approach which Martin Luther King Jr. criticized:
> [the] moderate who is more devoted to “order” than to justice; who prefers a negative peace which is the absence of tension to a positive peace which is the presence of justice
Politeness is considered more important than holding people to account. This acts as a strong protection of the status quo, i.e. it’s fundamentally conservative.
I’ve been observing another institution which follows that approach: the US Congress and Senate. It hasn’t been working out so well.
(Side note: I had to wait a few hours to be allowed to post this comment; how many comments are abandoned for that reason, or result in people going elsewhere, leaving this site to its self-reinforcing prejudices. It’s not the discourse encourager that some people imagine it is.)
Comment by Cider9986 8 hours ago
The thing you are missing is that discourse is terrible when people are rude. It's full of name calling, tone policing and moves away from the topic.
Comment by antonvs 1 hour ago
Edit: also, I find it revealing that you felt compelled to include that bit about "the thing you are missing", which is just a passive-aggressive way to call me an idiot who can't even see what you consider an obvious consequence. If you're honest with yourself, you'll admit that. I'd much rather someone be honest than fake polite.
Comment by datsci_est_2015 10 hours ago
I’m glad you brought it up here. Just because someone speaks well, intelligently, pleasantly, or even civilly doesn’t mean their message is righteous or just. Conversely, just because someone creates discomfort or says something impolite doesn’t mean their message can be disregarded. In fact, it’s those that are in power that often decide what or what is not impolite, and even speaking truth or justice to power in the first place can be labeled as impolite. George Carlin’s primary message as a comedian was essentially that.
Comment by inigyou 11 hours ago
Comment by infinite_spin 15 hours ago
Comment by inigyou 23 hours ago
Comment by chhxdjsj 19 hours ago
Comment by weregiraffe 15 hours ago
Comment by markus_zhang 1 day ago
1. Tokens are model-specific: e.g. tokens used by Anthropic cannot be used in models of other companies.
2. Tokens are generated by GPU cards. They measure the power of GPU cards.
3. Tokens cannot be separated from the models. You sort of "connect" the software part (models) into the hardware part (GPU cards) to use the tokens generated from the hardware.
Comment by capitalsigma 1 day ago
GPUs "generate tokens" in the same sense that human feet "generate steps"
You can't compare token counts across different providers to get an absolute measure of "total work done" for the same reason that you can't compare step counts across different people to get an absolute measure of "total distance traveled"
Comment by irishcoffee 1 day ago
You should do a bit of reading on what a token is. The short answer is that it’s a series of 2-4 bytes of information turned into an integer.
Your comparisons are akin to asking “are amazon gift cards the same as a bunch of pesos?”