RC RANDOM CHAOS

Inside China's Relay Market: How Stolen AI Tokens Get Resold at 95% Off

· via Hacker News

Original source

The relay market powering token resellers and fraud

Hacker News →

A sprawling gray market has grown up around reselling access to U.S. AI models like Anthropic’s, OpenAI’s, and Google’s, mostly serving Chinese developers hunting cheap inference. The economy runs four layers deep: card and account merchants supply virtual credit cards engineered to pass Western billing checks plus bulk-registered accounts; account pools aggregate hundreds of those accounts behind a single API and handle failover when keys get flagged; relays (or ‘transfer stations’) wrap that pool in a polished, billed, Chinese-language product; and at the bottom sit developers, startups, and SaaS firms — some running model distillation. Discounts are staggering, with tracked relays running 94–98% below official pricing; one operator advertised $3,333 of Anthropic credit for roughly $60.

Almost every relay is built on two neutral open-source OpenAI-compatible gateways, one-api and its more commerce-focused fork new-api. The software itself is legitimate and widely self-hosted; a relay only crosses the line when its channels are stocked with stolen, leaked, or pooled keys and resold against providers’ terms. The supply of abuse comes through free-trial farming, chargeback fraud, stolen and prepaid cards, and proxying traffic through poorly guarded support chatbots — plus an emerging ‘denial of wallet’ tactic that floods a provider with requests purely to burn its spend, with no profit motive.

The market is strikingly mature: price-comparison sites, affiliate programs, and even a directory (hvoy.ai) that raffles off fifty $100 API keys daily using the same provably-fair cryptographic scheme as crypto-gambling sites. The ten highest-traffic relays pull a combined 3.6 million monthly visits. The author expects abuse to intensify at the application layer as labs roll out KYC and identity verification — the fraud won’t vanish, it will just relocate. There’s no clean fix; defense is a cat-and-mouse game centered on raising the cost of bulk account creation, capping fresh-account spend, and detecting automation.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.