Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

A grey market for stolen AI credits gets an HN explainer

A deep dive mapping the underground supply chain for reselling stolen or pooled Claude and Codex API access, card dealers, account pools, relay panels.

Enterprise DNA |
A grey market for stolen AI credits gets an HN explainer

AI Pulse · Under the Radar

The play

Ban unofficial AI-credit sources, rotate exposed keys, and audit usage for suspicious discounts or shared accounts.

There’s a piece making the rounds on Hacker News that maps out something most business owners have never thought about, a grey market for stolen AI credits. It hit the front page with 155 points and 60 comments in a few hours, which tells you plenty of people recognized what it was describing.

The short version is this. Somewhere out there, people are getting access to stolen or pooled logins for Claude and Codex, then reselling that access through card dealers, account pools, and relay panels, at 94 to 98 percent off official pricing. If that discount range holds up, it means someone could be running real production workloads on API credits that were never legitimately paid for, and doing it at a fraction of the normal cost.

Why should you care if you’re just trying to run a business, not a hacking ring? Two reasons. First, if your team or a vendor is using AI tools priced suspiciously cheap, it’s worth asking where that access actually comes from. Underground supply chains don’t come with warranties, and accounts built on stolen credentials can vanish overnight, taking your workflow with them. Second, this is a signal about how valuable AI API access has become. When something is worth stealing and reselling at scale, with dedicated dealers and panels built around it, that’s a sign the underlying resource matters more than most people assumed a year ago.

The report itself is being treated as a developing investigation rather than settled fact, so treat the specific numbers as reported, not verified. Still, it’s a useful reminder to keep your own AI access clean, tracked, and tied to accounts you actually control. That kind of visibility into who’s using what, and how, is the kind of thing we build into an AI command centre, so nothing shady ends up quietly running through your business without you knowing.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.