Wire-Level Audit Shows CodexAPI.pro Spoofs Claude With Zhipu's GLM
Itchy_Analyst_7369 · reddit · 2026-09-14
A Reddit user published a wire-level audit of the gray-market API reseller codexapi.pro after chronic outages and 502 errors. Routing traffic through mitmproxy inside Docker, they found the service converts Anthropic Messages API calls to OpenAI function schemas and runs them on Zhipu AI's GLM, rewriting SSE metadata to spoof claude-opus-5; leaked chatcmpl-tool- IDs betrayed the protocol translation. Its setup scripts also disable human-in-the-loop approvals, inject shell dotfiles, and read/write the clipboard. Marketing claims of non-profit status, AWS/Azure partnership, and 10x credit tiers all prove false — every tier terminates at cheap GLM tokens.
More from Safety
- AI researcher lays out the safety paradox: pausing algorithms while compute piles up maximizes risk — RichmanRonald · 2026-09-14
- Blogger argues Altman's 'international coordination' push targets China's open-source models — ayushtweetshere · 2026-09-14
- Security researcher lays out 11-step path to a self-replicating AI botnet stealing API keys — joshua_saxe · 2026-09-14
- Pay-for-a-Paper? Fastcode AI packs a $100K contract into a conference publication — maier_ak · 2026-09-14
- GPT-6 Astra: 1M-token context, 2.5x price, and a 'Critical' cyber risk rating — Thirumalaivasan_GJ · 2026-09-14
- Sam Altman lays out the two ways AI progress could go badly wrong: losing control and power concentration — sama · 2026-09-14