LOADING THE FEED ▮
NICHE OF ONE
--:--
← The Feed

The Classifieds Nobody Posted: Inside the Black Market Reselling AI Access at 97% Off

/A gray-market economy is reselling Anthropic, OpenAI, and Google API access in China at up to 98% off, built on stolen cards and abused free trials. What the four-layer supply chain teaches about pricing, trust, and every leak a metered product will eventually spring.

post to X email it
Halftone manga-style illustration of a wall of wooden pigeonhole mail slots filling the frame, nearly every compartment empty, a narrow counter shelf running along the bottom.
// the everything pass All-Access The whole catalog, the members vault, and the back room where the operators talk shop. $37/yr →

Somewhere there is a want ad that reads, in effect: $3,333 of Anthropic credit, yours for 425 RMB. No questions asked. Nobody at Anthropic wrote that ad. Nobody at Anthropic approved the price. It ran anyway, and it sold, and it kept selling until an investigator went looking at why a v2ex forum thread was casually discussing where to buy frontier-model tokens at 98 percent off list.

That investigation, reported by Matt Lenhard, maps a reseller economy that has grown up in mainland China around exactly one product: access. Not the models. Not the outputs. Just the door.

I have refused ads for less than this, and never on principle. On arithmetic. The desk takes money for words, and the question that gets answered before a listing runs is whether the thing for sale can actually exist.

This one can. That is the uncomfortable part. Every line in that ad is true, the price is real, the delivery works, and it is still a stolen supply line wearing a wholesale coat.

TL;DR: A four-layer gray market has formed around reselling API access to Anthropic, OpenAI, and Google at 94 to 98 percent off official pricing, using stolen cards, abused free trials, and pooled accounts run through open-source proxy software. The ten highest-traffic relay sites pull 3.6 million monthly visits combined. It is a distribution story, and it runs on the same instincts that drive any honest reseller (supply, markup, customer support, retention) pointed at a stolen supply line instead of a legitimate one.

Four layers, stacked like any wholesale operation

Four layers, stacked like any wholesale operation you’d recognize:

Upstream, card-and-account merchants supply the raw material: virtual credit cards and bulk-registered accounts, sourced however they’re sourced. Midstream, “account pools” take hundreds of those upstream accounts and turn them into a single, load-balanced API endpoint, handling failover so no individual burned account takes the whole operation down. Downstream, the relays wrap that pooled access in a Chinese-language storefront, complete with billing and customer support. And at the end, developers, startups, and SaaS shops buy tokens the way anyone buys tokens: because they’re cheaper than the sticker price.

The plumbing running most of this is open-source. Two projects, one-api and its more actively maintained fork new-api, are OpenAI-compatible gateways built to manage channels, pooled keys, user quotas, and billing multipliers. They were built for legitimate self-hosting. They work exactly as well for a reseller running four hundred stolen accounts through a single meter.

That’s the part worth sitting with. Nobody had to write malware. They wrote a good product and pointed it at bad inventory.

What’s the actual hustle, and where does “discount” become “fraud”?

The discount is real. The margin comes from five places, according to the investigation: automated free-trial abuse, chargeback attacks after a billing cycle closes, prepaid-card exploitation up to the card’s limit, quietly routing traffic through unprotected support chatbots that have model access baked in, and straightforward denial-of-wallet, burning someone else’s spend cap because you can.

None of that requires a genius. It requires patience and a spreadsheet. That’s true of most fraud and most growth hacking both, which is the uncomfortable overlap here. A legitimate referral loop and an abused free-trial farm run on the identical mechanic: get in cheap, get in fast, get in a lot of times. One version violates a terms-of-service page. The other one is a case study on a growth blog. The tooling doesn’t know the difference. Only the intent does.

Why does anyone buy stolen access instead of just paying the list price?

Three buyer profiles, and only one of them is doing it to save a few bucks on a side project.

The first is ordinary price sensitivity: developers and small shops in a market where the official rate genuinely doesn’t pencil out. The second is geography: routing around restrictions that make frontier models hard to reach directly. The third is the one that should worry a platform more than fraud does: model distillation. Buying cheap, high-volume access specifically to harvest outputs and train a competing model on them. The investigation calls this a multi-billion RMB industry on its own, running quietly downstream of a black market most people assumed was just cheap-dev-tools noise.

That’s the tell that this isn’t really a fraud story. It’s a supply-chain story wearing a fraud story’s clothes. The theft gets the access. The distillation is what the access was for.

Every metered product grows a classifieds section it never authorized

Every product with a meter on it will eventually get a shadow classifieds section it never authorized. That’s true of software seats, of streaming logins, of course bundles, of anything priced per-use behind a login wall. The instinct that builds a relay site is the same instinct that builds an affiliate program: find the arbitrage, wrap it in a storefront, handle support so buyers trust the deal. The only difference is which side of the wall the storefront started on.

The recommended fix in the piece isn’t dramatic. Make bulk account creation genuinely annoying. Flag virtual and prepaid cards at signup. Watch the gap between registration and first token pull, because a real developer takes longer to get going than a bot farm does. Cap spend per key, cap concurrency, reserve budget the way you’d reserve inventory. And when you catch it, throttle quietly instead of announcing the trap. The moment you tell resellers exactly what tripped the wire, you’ve handed them the fix for next time.

Throttle quietly. That is the only line in the whole report I would have written myself, and it is the one nobody ever wants to pay for.

That last one is the real lesson, and it has nothing to do with AI specifically. Every discount code, every referral bonus, every “first month free” has the same seam in it somewhere. Someone is already running the numbers on how to route around your price, and they built a support team to do it professionally. The question worth asking isn’t whether that seam exists. It’s whether you’d notice before 3.6 million monthly visits did.

Frequently asked questions

Is this actually a hack, or is it just resale?

Neither term fits cleanly, which is the point. No systems were breached to produce the access itself. The fraud sits earlier, in how the underlying accounts and cards were obtained. The relay layer on top of that is closer to unauthorized resale: legitimate proxy software, pointed at illegitimate inventory, sold through a normal-looking storefront with billing and support.

Are the specific discount and traffic numbers verified by Anthropic, OpenAI, or Google?

Not independently, as far as this draft can confirm. The figures (the 94 to 98 percent discount range, the $3,333-for-425-RMB example, the 3.6 million combined monthly visits across the ten highest-traffic relays) come from the investigation itself, which drew on a Chinese-language forum thread and the reseller sites’ own advertised pricing. Treat them as investigative reporting on an opaque market rather than numbers any of the three AI labs have put on the record.

One piece of it does have platform-side corroboration, though, and it is the piece that matters most. Anthropic went public in February accusing three Chinese labs of systematically harvesting Claude outputs to train competing models, saying it had detected over 16 million exchanges across 24,000 fraudulent accounts. That is the distillation layer described here, confirmed from the other end of the pipe by the company being distilled.

// comments
Full search on OneSearch: the network, the ring, and the open web →esc closes · ↑↓ move · ↵ opens