Investigation into the Gray Market for LLM Token Resale: API Key Pooling for Profit, Fraud and Abuse Coexist
Security researcher Matt Lenhard's investigation reveals that resellers aggregate API keys through abusing free credits, credit card fraud, and other means to resell LLM tokens at discounted prices, with the market particularly active in China.
Security researcher Matt Lenhard published an investigation on July 26, 2026, revealing a gray resale market that has formed around LLM tokens. Resellers aggregate API keys from multiple sources and provide access to buyers at a discount through proxies. Discounts are derived from abusing free trial credits, hijacking traffic from unprotected support bots, and exploiting stolen credit cards or initiating chargeback attacks. The proxy software used by these resellers is mostly open-source projects (such as one-api and its fork new-api), which are essentially legitimate API proxy tools used for load balancing across key pools. Buyers seek low-cost tokens, bypass geographical restrictions, or collect data for model distillation. The investigation extensively cites posts from Chinese forums as sources, indicating that this market is particularly active in China. For LLM providers, this ecosystem means that rate limiting alone is insufficient to prevent abuse; hard usage caps (such as spending or time-based limits) must be set to prevent illegal arbitrage of API keys.
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-07-27
- Last updated
- 2026-08-01
- Content type
- Newsflash
- Source material
- View original ↗

