Opens in a new tab

Table of Contents

Explore AI Summary

Share post on:

Tokens are work’s new currency. Fraud got there first.

Anthropic sells Claude Opus input tokens for between $4 to $5 per million, depending on model version. On Taobao, resellers move the same access…

Sift Author Logo
Ajay Gopal
black-dot
Press-Release-Tile-Image-Color-Pills_Blue

Anthropic sells Claude Opus input tokens for between $4 to $5 per million, depending on model version. On Taobao, resellers move the same access for a fraction of that price, sometimes as little as 10% of the list price. That gap doesn’t close itself. Something is funding it, and it isn’t one thing. It’s several kinds of fraud, stacked, each one hitting a different point in the customer journey.

Tokens are behaving like a currency, and fungible currencies attract thieves and counterfeiters.

We priced tokens like a utility: metered, published, predictable. But consumption doesn’t move like a utility bill. It moves like a market. Tokens are the unit code used to orchestrate work, so demand scales however fast the work scales, and every time a new model raises the ceiling on what’s possible, demand jumps ahead of supply. Whoever holds cheap access in that window, earned or stolen, holds a short-term edge in what they can build before pricing and capacity catch up. That’s the currency dynamic. Fraud is just the fastest vector exploiting it.

Old detection, new currency

Security researchers have mapped the mechanics. Resellers, sometimes called “transfer stations,” keep prices low by bulk-registering free developer accounts to farm introductory credits, splitting a single premium subscription across dozens of users, opening accounts with stolen card details, and in some cases paying people in lower-cost regions to hold accounts on their behalf. That’s signup fraud, payment fraud, and subscription abuse, running at once, inside one business.

Then there’s the sharper edge. Okta traced stolen session tokens from a 7 GB infostealer dump, pulled off close to 6,000 infected machines across 162 countries, now circulating on Telegram with money-back guarantees and round-the-clock support. One storefront calls itself, without much subtlety, Poison Claude. A stolen session token doesn’t just skip the password. It skips MFA outright, because the session already looks logged in.

None of this is marginal. Credential theft aimed at AI services grew 376% between Q4 2025 and Q1 2026. Okta’s team has told reporters abuse costs for some companies are doubling roughly every two months, with a few losing more than $1 million a day. 

Fraud now follows the money and the model release

Here’s the part most coverage of this problem misses: every flagship launch creates a predictable demand shock, and demand shocks are exactly where fraud gets its runway.

GPT-6 Astra is the cleanest live example. OpenAI shipped it September 3, 2026, and a day later Sam Altman was publicly apologizing for what he called a messy rollout, since broad access hadn’t actually begun yet for either API customers or ChatGPT subscribers. The strain didn’t ease once access opened. By September 10, 2026, OpenAI closed its top consumer tier, the roughly $200-a-month plan, to new sign-ups entirely, pushing new demand onto the API instead, and separately, reportedly warned that new Pro subscriptions could be paused altogether if record demand kept climbing, on top of a 4X cut to usage limits for existing users. The shift showed up in aggregate spend too: OpenRouter reported that its users spent more on OpenAI models than on Anthropic models the following week, the first time that had happened in more than two and a half years.

Jev, the decision-only model from TypeSafe AI, shows the same shock at a completely different scale, and it didn’t need a frontier chat label to cause it. Released September 15, 2026, Jev became the fastest-adopted model in Vercel’s AI Gateway history, reaching close to 13% of paid teams within 24 hours, more than double the early adoption rate of the GPT-5.6 family and over six times Fable 5.1’s. TypeSafe’s own API reportedly buckled under the load, briefly unable to serve requests at all. One model built for chat, one built to never generate a word of text, and the same result inside two weeks: demand outran supply before the ink on the launch post dried. TypeSafe named it after the Jevons paradox, the idea that cheaper access increases consumption rather than curbing it. Fitting, given the currency dynamic above.

That’s not a one-off rollout hiccup. That’s the pattern every flagship launch will follow: capacity lags hype, official access gets rationed, and the gap between what people want and what they can legitimately buy gets filled by whoever moves fastest, resellers included. If digital safety in this category means anything operational, it means treating the days around every major release as a known P0 window, not a surprise you discover in the incident channel.

Why one tool can’t see the whole thing

Every fraud type in that chain is individually catchable. A signup fraud tool flags the bulk account creation. A payment fraud tool flags the stolen card. An account security layer flags the impossible-travel login. Each one, correctly, tells you it caught something.

What none of them tells you, on its own, is that the same actor opened the account, split the subscription, and is now logging in on a session that was never issued to a real person. That connection only exists across the journey. No single stage holds it. A vendor selling account defense with no visibility into payment behavior sees a login anomaly. A vendor selling payment fraud with no visibility into account creation sees a chargeback. Neither sees the business model behind either one.

If fighting fraud is a team sport, the tool vendors don’t talk to each other. Network data and machine learning aren’t the differentiator anymore; everyone in the category has both. Every merchant ends up assembling its own constellation of point tools just to approximate what should have been one system, and pays for it three times over: licensing each tool, carrying the compliance overhead of running multiple vendors, and engineering the integration to stitch them together in the first place.

Verticalizing for today’s fraud isn’t a durable bet, either

The instinct, once you see the fragmentation, is to build or buy a tighter, more specialized stack for exactly this problem. Resist it. This ecosystem moves on the model release calendar, not the enterprise procurement calendar, and a system finely tuned to catch this quarter’s fraud pattern is already behind by the time it’s deployed. Astra proved that in a week. Jev proved it again eleven days later. The next flagship release will prove it a third time.

A buyer who optimizes hard for the current shape of the threat is optimizing for something that isn’t going to hold its shape. What ages well is modularity: a system built to add new signal types and new fraud vectors without a re-architecture, but connected enough that those modules actually share context instead of operating as separate silos. That’s a harder thing to build than a sharp point solution. It’s also the only version of this worth buying for the long term.

Dare to grow differently.

Flip the switch on fraud-fueled fear. Make risk work for your business and scale securely into new markets with Sift’s AI-powered platform.

see sift in action
  • remitly
  • swan
  • yelp-white
  • taptap
  • remitly
  • swan
  • yelp-white
  • taptap