This is a transcript of Inside the Black Market for Stolen AI Tokens | 001 with Matt Lenhard, Founder of Vectoral. Please note that the transcript has been lightly edited for readability and may contain errors.
Table of Contents
00:00 The underground market for stolen AI tokens
01:33 $10M in 48 hours and why Matt quit
02:38 How the stolen AI token market works
08:07 Who buys discounted AI inference?
10:01 How Matt chooses what to build
13:11 Going inside the token broker market
17:22 Model distillation and frontier AI
19:33 Denial of wallet attacks
23:53 How Vectoral detects AI abuse
26:06 Where AI fraud goes next
29:40 AI regulation, jobs and moving fast
32:25 What's next for Vectoral
Transcript
The underground market for stolen AI tokens
Jared S. Taylor
00:00
Before we talk about your company here today, I want to talk about what you found. You published a piece in June that mapped an entire underground economy selling stolen AI tokens. Start at the beginning. How did you end up on a Chinese forum reading operators describe their business?
Matt Lenhard
00:18
Yeah, so it all started from my own experience. I previously worked on an AI gateway, and I kept getting paged for abuse.
It's a Saturday night, I'm out to dinner with my wife, and we get a Slack message: we're getting hit for $60,000. I go home, merge a fix, it goes away for a week, and then it comes back again and again and again.
It was like, okay, I need to start looking into this.
I started talking to friends. I was like, hey, are you seeing the same things? And I was pretty shocked at the scale of it.
I would talk to friends who were seeing over $1 million in token fraud per day, others who were seeing $10 million a month.
At that point, I realized this had to be more than just individual bad actors. What I would come to find was that there's essentially an entire underground market facilitating the trade of stolen tokens.
Jared S. Taylor
01:27
You said a million in one day in token fraud you'd see?
$10M in 48 hours and why Matt quit
Matt Lenhard
01:33
Yeah. I think the worst I saw was $10 million in 48 hours.
That was actually the breaking point. I quit my job a few days after that because I was like, this is something that I need to solve. For my own sanity, for friends.
It's rare to see a problem like this, something that I was passionate about, was excited to solve, and that frankly needs to be solved.
Jared S. Taylor
02:06
And when you look at this space, when I was doing my research, and you and I talked a little bit about this before the recording, there's not much on what you're building and what you're solving.
So I was very excited to chat with you here today about it.
What I would love to do is explain the market to me and the audience like we've never thought about this before.
There's a supply chain. Who's at the top? Who's in the middle? Who's actually buying?
How the stolen AI token market works
Matt Lenhard
02:38
Yeah. So to take a step back, what exactly do I mean by stolen tokens?
Essentially, there are hundreds of websites out there getting millions or tens of millions of visitors a month, depending on the site, where you can go buy Anthropic, OpenAI, DeepSeek, whoever you want, for up to 98% off.
I was a victim of the supply side of that market. They need a way to essentially get those tokens that they're reselling, and we were a victim of that.
There are multiple layers to it. It's actually a pretty sophisticated market.
When I first started looking into this in June, or really earlier, in early May, there wasn't much talk about this on the Western internet at all.
They're called relays or transfer stations, and they're the marketing arm, almost, of the token resellers.
There's a lot of prebuilt infrastructure to quickly spin up your own relay. There are GitHub repos out there with one-click deploys. It'll spin you up an entire application where you just load in accounts. It has reseller functionality built in, and then you can essentially resell inference.
That's the top layer.
There are all of these sites that are essentially lead generation and marketing. Surrounding them, there are affiliate sites that get paid to send referrals to those sites. There are price comparison websites. There are sites that do model verification for these services to make sure they're actually selling you the model they say they are.
Beneath that are the account pools.
There are a bunch of sites out there that facilitate the trading of accounts. What do I mean by that? You can go out and buy Anthropic accounts, OpenAI accounts. Name any AI app you can think of, and there are probably accounts being traded on one of the marketplaces.
Underneath that are KYC verification bypass services. If you're looking to register a bulk number of accounts and need to pass KYC requirements, they'll help you do that.
There are also card pools if you're looking to bypass geographic restrictions around cards.
This all intermingles. Some of the relays are more vertically integrated, some aren't.
That maps out the supply side of the market.
The tactics they use to get these tokens really differ. They're pretty clever.
It could be the account pools I mentioned, where you get more tokens than what you'd actually be paying for via API.
There's free-credit and free-trial farming. They sign up for a bunch of accounts and take the free credits.
Something I'm seeing a lot more of now is chargeback fraud and stolen-credit-card fraud. Possibly because it's just an easier form of fraud if you have a stolen credit card than existing methods like ecommerce or marketplace card cycling. It's much easier to perform the token reselling.
Any type of open inference is also another source they'll supply from.
If you've seen a chatbot on some website, they'll figure out how to proxy traffic through that and resell that inference.
That maps out the supply side of the market.
On the demand side, you have a mixture of people and consumers.
At the most basic level, you have people looking to get around geographic restrictions. Maybe they can't sign up from their own country, or the model providers have restricted that country's access, and they just want to use the models. They'll do what they can to get around those restrictions.
You also have consumers looking for cheap tokens. They don't want to pay list price.
I've seen actual businesses as well where they're running full SaaS-style applications based on these tokens and simply want to beat their competitors on price.
Then there's some level of this that is model distillation. Companies looking to hide their footprint when distilling frontier models.
That's the long-winded way of mapping out both the supply side and the demand side of the market.
Who buys discounted AI inference?
Jared S. Taylor
08:07
Obviously, this was bad enough that you're like, I want to go and build a solution.
What's the penalty for any of these, I guess you can call them bad actors, consumers, whatever you want to call them, for the ones that are selling and the ones that are using it?
Because it is, in some way, fraud, right? You're not supposed to be using these tokens that you did not pay fair value for.
I don't want to put words in your mouth, but what are they doing? Do they just ban your account if they find out you're using these discounted tokens?
Matt Lenhard
08:46
Yeah. Frankly, I don't think there's really much they can do more than just ban the account.
These mainly aren't being run by U.S. citizens, from what I can tell.
So the most that typically happens is the account gets banned, the relay sources some new accounts, some new supply for the tokens, and the process repeats itself.
It's kind of a cat-and-mouse game.
Jared S. Taylor
09:15
By the way, the fact that basically the steepest penalty is your account gets banned makes me like what you're building even more. It's super interesting.
One of the things you said is that you had the number that made you want to quit. What were some of the other factors that led up to that beyond seeing these stats?
You're a serial entrepreneur. This is not your first rodeo. Every company you've started solved a problem you were facing.
What goes into deciding what your next business is going to be beyond just the statistic you told us about earlier?
How Matt chooses what to build
Matt Lenhard
10:01
Yeah. I really wanted to be thoughtful about the next company I worked on.
It's funny how, over my life, my thinking has changed about the importance of the idea.
For the longest time, I thought it's all execution. That's the most important thing.
And while I do think that's important, having a good idea frankly makes things a lot easier.
You don't necessarily have to nail the execution as much if there's a strong pull. If people really need what you're offering, you can make a few more mistakes along the way and still be okay.
One of the core things I was looking for in the next thing I wanted to start was an initial subset of people where this was a hair-on-fire problem they were dealing with.
They couldn't find a solution for it. Maybe they were building something in-house, but they had tried a bunch of things and nothing had really solved the problem.
That stood out for me with this because I had tried a bunch of solutions and none of them really solved the problem. It just kept coming back, and I was getting tired of dealing with it.
I was almost at the point where we would have paid for something. If somebody came and said, hey, let me solve this for you, we would have been pretty happy.
That was a pretty important piece of it.
The other was that I thought there was a great story to be told here.
I think that's really important when building a company. A lot of building in the beginning is telling your story, whether that's fundraising, talking to customers, or writing about the product.
Everything is a bit easier if you have a compelling story around what you're talking about.
I thought that was also here, that there was essentially this underground market I'd stumbled upon.
It was compelling to me. I found myself in these forums late at night, these WeChat groups, and I couldn't get enough of it.
And I thought, I don't think anybody else will either. People are going to want to know about this.
That was the next biggest thing.
The third is that a startup is a long-term commitment. You're getting ready to dedicate a large portion of your life to something, so it has to be something that you care somewhat about.
Does it get you excited?
You have to be able to wake up in the morning and look forward to what you're working on or the problem you're solving.
I was excited about the problem. It was interesting to me. It was something that I had dealt with, my friends had dealt with, and I felt good about trying to solve it.
Going inside the token broker market
Jared S. Taylor
13:11
I want to go back to something you mentioned.
Through your journey and discovering this opportunity, you would go into these forums.
As I was researching you, there was a little bit about the story of discovering these forums.
You would actually email the brokers, right? And then you also listed your own credits for sale just to see the other side of the funnel.
Tell me about that.
Matt Lenhard
13:40
Yeah. Part of this is kind of funny. There's a little bit of investigative research.
Because it's so new, in order to understand how this really works, I needed to stick my neck out a bit.
I talked to a bunch of friends who were starting to see this, and they had forwarded me emails from people trying to sell them credits at a steep discount.
I essentially started emailing them all.
I got on Telegram and all of these messaging platforms and just started reaching out.
The numbers were shocking.
I had someone offer me $3 million a month in OpenAI inference at something like 60% off.
I'm assuming it's stolen somehow. They're doing something to get those discounts.
Part of it was really trying to understand the motivations and methods of the supply side of the market.
How is this being facilitated? Who are the players? How do they think? What are they doing?
The only way to really figure that out is by talking to them.
Jared S. Taylor
15:02
As you're doing this, I'm assuming you're having some real fun too.
When you're chatting with these people on Telegram, did everyone seem like it was just another business when they were interacting with you? Like it was no big deal?
Matt Lenhard
15:23
Yeah, frankly, that's kind of how it feels.
It's just like I'm another customer.
Here's our rates. Here's how you integrate.
Some of these services offer invoicing, net-30 payments, enterprise pages for if you're a larger company and want to work with them.
They've got all of the typical motions you'd expect from a SaaS startup.
Jared S. Taylor
15:57
As you were doing your research, obviously you started building your initial assumptions and where you wanted to go with this product.
Was there anything, as you went further down the rabbit hole, that surprised you the most?
Matt Lenhard
16:14
Yeah. I think the biggest thing has always been the scale.
That was the most shocking at the start, when I started seeing the numbers of how bad this was, how popular these sites were, how many visitors they were getting.
Those were all big aha moments for me.
Also the breadth.
A lot of companies I talked to were feeling this.
It could be a small company. It could be a large enterprise. It almost didn't matter what the shape of that organization was.
Most were feeling it in some way if they had really started looking into the data.
For a while, everyone has been kind of token-maxing, so they weren't looking at the data.
Now that the market is starting to turn a little bit and people are starting to ask questions like, how are our tokens being used? Are we getting benefits out of this? What does spend look like?
I think more and more of this is being uncovered.
Model distillation and frontier AI
Jared S. Taylor
17:22
What are your thoughts on these frontier models versus what you also hear a lot of people talking about now, which is running models privately?
Obviously, for what you're building, those frontier models are of the utmost importance.
But from your technical background, what are you seeing when it comes to these frontier models? What are your thoughts on how the private models have really stepped it up over the last few months?
Matt Lenhard
17:55
Yeah. I think there are a few interesting things here.
The first is that I actually think part of the fraud is almost less about the model.
Some of it matters specifically for distillation, but it's really more about, especially on the stolen-credit-card front, how easy is it to turn that into a dollar?
I don't even know that what the input is matters as much as the fact that it's very easy to exchange this unit for some form of currency.
That being said, the frontier models definitely have the biggest targets on their backs. They're being hit the hardest by this.
And downstream of that, why do I think not all, but some, of these other open-source models have caught up so quickly?
Well, it's distillation.
There are services like these relays, and it's funny seeing people in the press saying there's no distillation happening.
You can go to any of these forums and they're very openly talking about how much money they're making selling to these companies doing the distillation.
It's very obviously happening if you spend a little bit of time researching the market.
I think that is a large reason why they've been able to catch up so quickly.
Denial of wallet attacks
Jared S. Taylor
19:33
Something I want to go back to: as I was doing this research, you described something called denial of wallet, where there's no financial motive at all.
Someone's just burning your money, essentially.
That would suggest that every company that shipped an AI feature also shipped a business model where a stranger can spend the cash.
Is that a temporary artifact of how fast everyone moved, or is it structural?
Matt Lenhard
20:04
I think it's an interesting change in the structure of how applications are being built.
That was very wordy, so let me break down what I actually mean.
We've never really had an HTTP call that could cost 30 cents, a dollar, or more.
And now we do.
Now you can have a user sign up for your app and hit some endpoint that maybe generates an image, or there's some inference backing it, and they can cause financial harm where they're actually spending your money.
For a typical SaaS application, somebody spins up a bunch of free accounts, who cares? It's not the end of the world.
But now they can spin up a bunch of free accounts, maybe you give them five chats free or have some AI feature bundled in, and they just want to hammer that AI feature because they don't like you.
I've seen stories of this where a friend ended up on some forum and they didn't like him for whatever reason.
They put a bunch of scripts together to spin up a bunch of accounts and essentially drain his token spend for no real reason other than they just didn't like him.
It's similar to a DDoS attack, where somebody doesn't like you and they want to take down your site just because they're kind of an asshole.
But this time there are actual dollars tied to it.
Jared S. Taylor
21:52
Okay, so you just brought up something.
In the past, a lot of these companies would have to worry about a DDoS attack.
Obviously that's not good, but it ends up being more of an inconvenience to get everything back.
Now we're talking real dollars at stake.
This really should be a problem that more people are talking about across the board, right?
Matt Lenhard
22:20
Yeah, absolutely.
With DDoS, they take down your site. There are some reputational problems with that.
But even for the most part, people are understanding. Hey, we got DDoSed. Your customers are going to feel bad a little bit.
But with denial-of-wallet attacks, it's an actual dollar.
If they figure out what that inference endpoint is, maybe you're just a typical SaaS app, but somewhere in your application there's a way to interface with AI.
If somebody figures that out and figures out how to set up enough accounts, or how to get to that endpoint, they can hit you for real dollars.
It's crazy.
And it's not cheap either.
I think it's something that a lot more companies should be thinking about.
Even just putting in the basics, tracking, helping them figure out: how would you know if this was happening? What are the bare-minimum steps you can take to shut things off if it is happening?
I've seen stories where larger organizations are getting hit for seven figures before they actually notice.
How Vectoral detects AI abuse
Jared S. Taylor
23:53
Act like I'm a potential customer and you're pitching Vectoral.
What is your pitch? How does it work? And what does a core buyer look like today, or what will one look like?
Matt Lenhard
24:05
Yeah, I'll put my sales hat on.
Very different hat.
Frankly, a lot of what I do now is just explaining the problem and talking people through what I've seen work, what doesn't work, and what the basic steps are they can take.
At our core, what we've built is a classification model that ingests a lot of signals that we've seen correlate with this type of abuse.
We have labeled data of the abuse, and from there we've built a classification model that can predict how likely it is that the person, or that individual inference request, is abusive.
What was core for us was that you need to look at a lot of different signals.
Maybe that's why there wasn't an out-of-the-box solution for all of this when I first started looking into it.
You need to look at information on registration. You need to have an idea of who's signing up, why, location, all the metadata there.
You need to have a lot of data about the browser being used.
Most client-side detection can be bypassed, but it's a good additional layer.
Then you need another set of events collected from the inference request itself.
If you take every single step of that user's journey to get to the actual inference request, you can essentially build a model of who that person is and how they're using the application.
We use that to inform whether that person is potentially abusing the system.
Where AI fraud goes next
Jared S. Taylor
26:06
As Anthropic and others continue rolling out identity verification, you've said the abuse will not disappear, it'll just move.
Can you give me a specific prediction?
Twelve months from now, what's the fraud? What's the fraud that doesn't have a name yet?
Matt Lenhard
26:33
What's the next form of token fraud?
I think this moves to the application layer next.
That's my hunch.
Anthropic starts rolling out more KYC controls and identity verification.
The demand side of the market will still be there, and so people will figure out a way to find that supply.
It's going to be less sophisticated organizations, or people who haven't had to deal with this yet, that are the next target down the line.
My other hunch is that the frontier model labs are always going to be dealing with this in some sense.
When Anthropic rolled out KYC, there were listings for KYC bypass within a day.
There are a bunch of ways to get that bypassed. There are actually entire identity providers that facilitate these KYC control passes.
But it's going to push a lot of this down-market.
If an easier path for them is to just hit the application layer, that's what they're going to do.
I think we'll see that in the short term. I'm already starting to see that.
I think we're going to see more credit-card fraud move from existing vectors to tokens.
The market is newer. Companies don't have the required checks set up yet to really stop this type of abuse.
The actors are very sophisticated.
And as an application, if you get a chargeback, even if you win that chargeback, you still get charged a fee on it.
At the end of the day, you're still losing money.
That's what I think of in the short term.
In the long term, what we're seeing right now is token fraud or inference fraud.
I think long term we're going to see almost fraud for agents, which I think is different than agentic fraud.
Not agents performing fraud, but fraud being pushed onto agents.
You set up some agent to do something. Somebody hijacks that agent, uses all your money, and does something completely different that they want to do.
When I think about how cybersecurity attacks of the future are going to happen, I think it's going to be hijacking agents to do their dirty work, to hide their tracks.
I think that's what we see long term: fraud moving toward agent hijacking, people taking your agent to do what they want.
AI regulation, jobs and moving fast
Jared S. Taylor
29:40
And that's part of why it's so important that, as an industry, we just keep moving forward, right?
I think everyone, every entrepreneur, the technical community, understands this.
But when you look at the focus on America and Americans today who are anti-AI, I keep hearing that there are talks within the government about installing something like the FDA for reviewing AI models.
I don't think people who aren't on top of the technology and learning realize how dangerous it would be if we had to slow down our progress here while every other country, like China, continues moving forward.
Even if there are jobs lost, because of all the other countries, what's happening, and the progress and how fast these technologies are growing, you kind of have to keep growing versus ever pausing.
It's just a wild time that we live in right now.
Matt Lenhard
30:47
Yeah, totally.
I think there's some level of, if we want to be at the frontier of this new technology, we just have to move quickly.
Like I said earlier, I don't think the labs have done a great job in the press. They've certainly not made themselves out to be the good guys here.
But I do believe that it's core to the future of our country, for future generations of America, that we are at the forefront of this.
I don't really buy that having some regulated thing that looks at models is going to safeguard us from what's possible here.
I think that's kind of a pipe dream.
We need to let the market evolve a bit before we decide what that should look like.
I don't think we need to rush into that.
I think we should be thoughtful about how this industry looks in five to ten years.
And for now, let it keep rapidly evolving.
I'm also not personally in the camp that AI is going to take all jobs.
I think jobs will change, but people are going to want to continue working and organizations are going to want to continue hiring people.
There are going to be shifts in the labor market, but long term I think everybody benefits from this.
What's next for Vectoral
Jared S. Taylor
32:25
Before we start to wrap up here, one or two more questions for you.
I really appreciate your time here today. This has been a fun conversation.
Is there anything you can tell us in regard to Vectoral that you're building now that maybe you haven't spoken much about yet, or you're about to announce coming up?
Anything you want to say here?
Matt Lenhard
32:48
Yeah, that's an interesting question.
We have a few things a bit under wraps, partially because we like to keep how a lot of the detection algorithm works close to our chest.
That's kind of our secret sauce.
If the other side knew every signal we looked at, it probably wouldn't be as effective.
But something I'm super excited about is the scale of labeled data that we're rolling in now.
It's made some great improvements to the classification algorithm.
And we're thinking about what trust and safety and abuse look like for an agentic world.
We've got a lot of really cool things planned around not just token fraud, but abuse against AI and agents more generally.
What can we do to help stop that?
And, more importantly, what tools can we give people so that internally at their own organization they can do their job better to stop this stuff?
I think that's core to the whole AI thing.
We're giving people tools to do a better job.
We're not taking their jobs. We're helping make their job easier.
Jared S. Taylor
34:15
Who should reach out to you after they see this? Who do you want to reach out to you?
Matt Lenhard
34:21
I would say generally, I love talking about token fraud.
Anybody who's interested in this space and wants to learn more, I'm always happy to chat.
Anybody who wants to solve this, we're hiring. I'd love to talk to you.
Anybody who's faced this, I'm happy to share what works or what doesn't.
Or anybody who's worried about this.
Again, I can share what I've seen, how the attack vector works, and what the bare-minimum things are you can do to prevent it.
