The email landed in a founder’s inbox with the subtlety of a brick through a window: “I have Millions of api credit so i am looking for partnership. I can provide for long term.”

Within weeks, another founder received a more polished pitch: direct relays to OpenAI and Claude at 40, 50% cheaper than list price. Just swap your API key to a different endpoint, and the savings start flowing.

This isn’t a niche hustle. It’s a rapidly professionalizing shadow economy built on one uncomfortable truth: AI credits have become a pseudo-currency, and nobody’s in charge of the exchange rate.
The Birth of the Token Broker
Startups swapping unused credits with each other is old news. Founder forums and private groups have been doing informal deals for years. But as security researcher Matt Lenhard discovered while investigating the token relay market, something shifted. Brokers are now actively cold-emailing founders, buying up unused credits, and reselling them at margin.
When Lenhard reached out to one broker directly, the conversation revealed just how industrialized this has become:

The broker’s account can spend $100,000 per day. They don’t hand over provider keys directly, instead, they act as a proxy that picks from a pool of keys and forwards requests. Billing happens after usage milestones, giving buyers the illusion of a legitimate vendor relationship.
That’s the key architectural detail most people miss. These brokers aren’t reselling credits like gift cards. They’re building relay infrastructure that sits between you and the model provider. Every request you send goes through their proxy, touching their key pool, their logging, their security posture, or lack thereof.
The Marketplaces: From Telegram Channels to Professional Platforms
The supply side has organized itself faster than the demand side can ask questions.
AI Credits bills itself as a credit marketplace, and its seller listings read like a who’s who of AI infrastructure, MiniMax, ElevenLabs, Google Gemini, OpenAI, Microsoft Azure, and Anthropic, with discounts ranging from 30% to 80%.

The onboarding process is almost laughably straightforward. Sellers fill out a form specifying provider, credit type, credit value, and their desired discount, which must fall between 40% and 80%.

Lenhard’s own test listing, $200,000 in OpenAI credits and $10,000 in Anthropic, sat pending approval when he checked. The machinery works.
But the marketplaces are only part of the story. CheapCredits and similar “bulk discount routers” like Tokvana and Neokens have taken a different approach. Instead of selling credits, they position themselves as API routers that pass along savings from “bulk pricing.”

Here’s where the skepticism should kick in. A flat 40% discount on every model, including GPT-5 series? That’s not how legitimate bulk pricing works. Even the largest enterprise customers don’t get 40% off list price across the board. As Lenhard notes, that kind of discount is “very unlikely unless you are one of the provider’s top customers.”
So where does the supply come from?
The Supply Chain: Grants, Subsidies, and Stolen Credentials
The credits flowing through these marketplaces come from several sources, and only some of them are legitimate:
Startup accelerator credits. Y Combinator’s Startup School program historically hands out OpenAI credits to participating founders. Those credits have a shelf life and can’t be transferred under the terms of service, but that doesn’t stop people from selling them.


Corporate accounts with suspicious spending power. The broker offering $100K/day in spend is likely running a pool of compromised or subsidized accounts. This is where the black market for AI API access using stolen credentials and evasion techniques comes into sharp focus. The Chinese “transfer station” economy has been doing this for years, using antidetect browsers, TLS fingerprint spoofing, and physical SIM banks to farm and resell accounts.
Stolen API keys. The LiteLLM supply chain attack in March 2026 exposed just how vulnerable this ecosystem is. CloudSEK’s research found that compromised packages potentially exposed credentials from more than 2,500 organizations, including AWS, Google Cloud, and Azure credentials, SSH keys, Kubernetes tokens, and, critically, LLM API keys and gateway configurations. The malicious packages were available for only 40 minutes, but as the FBI’s July 2026 FLASH advisory warned, harvested credentials remain usable for weeks or months unless rotated.
The LiteLLM attack highlights a critical point: AI infrastructure is becoming a strategic target precisely because it sits at the junction of data, identity, compute, and autonomous action. When attackers compromise an AI gateway or steal API keys, they’re not just getting model access, they’re getting a foothold into whatever systems those credentials can reach.
Why the Discounts Exist (and Why You Should Be Terrified)
Let’s be clear about what’s happening: a 40% discount on GPT-5 tokens isn’t a bargain. It’s a red flag.
Legitimate volume discounts from major AI providers exist, but they’re nowhere near 40% for most customers. When a broker offers that kind of pricing, one of several things is happening:
-
Subsidized credits are being resold. Accelerator programs and promotional credits are a form of subsidized compute. Reselling them violates terms of service and creates compliance exposure for the buyer.
-
Stolen or compromised accounts are being pooled. The broker’s proxy picks from a pool of keys, many of which may be harvested from compromised systems. You’re not just buying cheap tokens, you’re participating in the monetization of someone else’s security breach.
-
The broker is the middleman in a longer chain. The credits might pass through multiple resellers before reaching you, each taking a cut. The original source could be a hacked account in Singapore, a farm in Eastern Europe, or a well-meaning founder who didn’t read their TOS.
The “cheap credits” websites even try to look legitimate. CheapCredits has a Data Processing Agreement claiming GDPR Article 28 compliance and listing OpenAI and Anthropic as sub-processors.

This is theater. A DPA from a broker who can’t tell you the original account holder is worth the pixels it’s rendered on. If the underlying credits were obtained through fraud or TOS violations, your “compliant” deal is still contaminated.
The Scale Problem: Tens of Millions in Credits
Lenhard’s rough estimate of the market size: “across the sites, forums, and resellers I looked at, there are probably tens of millions of these credits being offered.”
Tens of millions. That’s not a cottage industry. That’s a market.
The infrastructure supporting it is equally organized. Telegram channels dedicated to buying and selling OpenAI, Claude, Gemini, Azure, and AWS credits have a few hundred subscribers each, enough liquidity to move significant volume.

This isn’t just about individual developers looking to save a few bucks. The suspiciously low AI API pricing enabling credit arbitrage and resale has created a broader arbitrage environment where price differentials across providers and regions make brokering genuinely profitable.
What This Means for Enterprises
If you’re an engineering leader, this should keep you up at night. Here’s why:
Your compliance posture is exposed. When a developer uses a discounted relay service, they’re routing your company’s data through infrastructure you don’t control, to accounts you didn’t provision, under terms you didn’t sign. The GDPR-friendly DPA is a fig leaf, the actual data flow is ungoverned.
You’re building on sand. The broker’s proxy can disappear overnight. If their pool of keys gets revoked, and it will, when the provider detects abuse, your production traffic dies with it. There’s no SLA, no support, no migration path.
You’re laundering stolen access. Some percentage of these credits come from compromised accounts. By buying them, you’re funding the credential theft economy and potentially exposing your own infrastructure to the same attackers.
This is the darker side of what CloudSEK and other researchers have been warning about. The threat landscape around AI infrastructure isn’t just about model attacks and prompt injection, it’s about the economic incentives that make AI access a target in the first place.
The Provider Response (or Lack Thereof)
The uncomfortable truth is that the major AI providers have been slow to address this. Token-based billing, credit pools, and prepaid usage systems were designed for convenience, not for detecting arbitrage patterns.
The shadow AI problem is being compounded by the credit resale problem. When employees can route around sanctioned procurement channels to get cheaper API access, they will, especially when the sanctioned path involves procurement cycles, budget approvals, and compliance reviews.
The crackdown, when it comes, will be messy. Providers will likely:
- Tighten credit transferability. The “no resale” clauses in TOS will be enforced more aggressively.
- Deploy anomaly detection. Unusual usage patterns, especially from accounts that suddenly start handling traffic from multiple IP ranges, will trigger automatic suspension.
- Force API key rotation. If a breach is suspected, keys will be invalidated without notice.
For enterprises, the message is clear: cheap tokens are expensive in ways that don’t show up on the invoice.
The Bottom Line
The AI credit resale economy is a symptom of a deeper problem: AI compute is expensive, access is fragmented, and the gap between list price and effective cost has created an arbitrage opportunity that’s too profitable to ignore.
But every arbitrage market eventually gets regulated out of existence. The question isn’t whether this one will collapse, it’s whether your organization will be holding the bag when it does.
If you’re using a discounted relay service, start planning your exit now. If you’re managing enterprise AI spend, tighten your controls on how API keys are provisioned and where development traffic routes. And if you’re considering buying “cheap” credits from a broker, ask yourself one question:
Where do you think those credits actually came from?
Because the answer is probably somewhere you don’t want your production traffic to be.




