Here is a more detailed article about how it works:
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
If your startup needs to run a million records of something, especially public data, through an LLM to extract the data you need, using bootleg tokens to shrink the bill starts feeling tempting.
If you're concerned about the data leaking, the biggest risk is that the API backends are quietly routing your requests to a cheaper model. You might be trying to buy Opus tokens but get Deepseek Flash responses.
Maybe this make sense, but anyway I have to pay a lot of attention at the output I get. Eg: who guarantees there is no prompt/sql injection? Especially if I have to load the output in some internal system.
I mean someone could try to sneak prompt injection into a text field, but the people buying black market resale tokens from third parties aren’t thinking about anything other than getting cheap output.