Summary
From the article:
A relay — or “transfer station” — is essentially a service that proxies traffic to U.S. models, often at a deep discount. For example, one operator’s price-comparison site listed a package that bought the equivalent of $3,333 worth of official Anthropic credit for 425 RMB — roughly $0.13 of usage per $1 spent.
[...]
Free-trial abuse. Abusers automate account creation en masse to claim free credits, then proxy that traffic back to their own end users.
Chargeback attacks. Abusers charge back their spend after the usage period ends to recoup their costs — or use stolen cards from the start.
Prepaid cards. Abusers fund accounts with prepaid cards capped at a set limit.
Open inference. Any support chatbot without strict guardrails is ripe for having traffic proxied through it.
Denial of wallet. Not strictly a relay technique, but an emerging form of abuse I’ve been tracking: attackers fire off a flood of concurrent requests purely to burn a provider’s spend. It can be facilitated by any of the methods above. The difference is there’s no financial motive.
[...]
The three main use cases seem to be cheap tokens, getting around geo-restrictions and model distillation. A few relevant quotes from the forum:
[...]
I was surprised by how mature the market already is. There are price-comparison sites for the relays, affiliate programs, and even gateway products. On the forums, consumer demand looks just as strong. And these aren’t fringe operations: the ten highest-traffic relays we track pull a combined 3.6 million visits a month between them.
My hunch is that things get worse for the application layer from here. As Anthropic and others roll out KYC controls and identity verification, the abuse won’t disappear, it will just move somewhere else.
[...]
A clear sign of how normalized this has become is that one of the relay directories runs a daily lottery for API keys.
[...]
The part that got me is the fairness theater. The draw is provably fair — the same cryptographic scheme legitimate crypto-gambling sites use to prove they didn’t rig the result. The random seed is the hash of the latest Bitcoin block, winners are picked with a Partial Fisher-Yates shuffle, and the full list of entries is published as a snapshot before the draw.