Investigation into the Gray Market for LLM Token Resale: API Key Pooling for Profit, Fraud and Abuse Coexist
Security researcher Matt Lenhard's investigation reveals that resellers aggregate API keys through abusing free credits, credit card fraud, and other means to resell LLM tokens at discounted prices, with the market particularly active in China.

Security researcher Matt Lenhard published an investigation on July 26, 2026, revealing a gray resale market that has formed around LLM tokens. Resellers aggregate API keys from multiple sources and provide access to buyers at a discount through proxies. Discounts are derived from abusing free trial credits, hijacking traffic from unprotected support bots, and exploiting stolen credit cards or initiating chargeback attacks. The proxy software used by these resellers is mostly open-source projects (such as one-api and its fork new-api), which are essentially legitimate API proxy tools used for load balancing across key pools. Buyers seek low-cost tokens, bypass geographical restrictions, or collect data for model distillation. The investigation extensively cites posts from Chinese forums as sources, indicating that this market is particularly active in China. For LLM providers, this ecosystem means that rate limiting alone is insufficient to prevent abuse; hard usage caps (such as spending or time-based limits) must be set to prevent illegal arbitrage of API keys.
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-07-27
- Last updated
- 2026-09-01
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

Visa and Mastercard Join Ant International on a KYA Interoperability Framework as Agent Identity Standards Begin to Converge

Consumers Use AI Assistants but Won't Hand Over Their Wallets: Visa Data Reveals the Agent Payment Trust Gap

SWIFT Doesn't Touch Money: How a Non-Settling Company Sat at the Center of Cross-Border Payments for 50 Years
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

