LLM token resale and fraud markets expose a new layer of API abuse

Simon Willison · rss · 2026-07-27

Simon Willison highlights an investigation into the market for discounted LLM tokens and the fraud ecosystem around it.

The report describes resellers pooling API keys from free trials, unprotected support bots, stolen cards, and chargeback abuse to offer cheaper proxy access to LLMs. The software stack behind these proxies is often open source, especially one-api and its fork new-api.

The buyers are looking for lower prices, geo-unlocked access, and sometimes data for model distillation. Willison says this makes him even more cautious about exposing LLM apps publicly, and argues vendors need strict per-key caps so apps can shut off the moment they hit a dollar threshold.

Original post →

More from Safety

Safety channel →