And so, like, whatever, the dine and dash that happens in restaurants is like a dine and dash, but it's for tokens. And unfortunately, at that point, again, this is AI, not SaaS. So the company has borne the costs of those tokens.
And sorry if that's obvious, and I guess I would be a terrible fraudster because it's not even super obvious to me. So if I get tokens for free, what do I actually do with them? So I guess if I get tokens from a general-purpose LLM like Claude or ChatGPT, I could see what I do with it if I go to Cursor or Lovable or ElevenLabs. So what is it that I actually do with tokens?
Yes, exactly. Okay, so what you do with it very much changes based on what's the service, what exactly were these tokens meant for? You hit the nail on the head for, okay, you just get the tokens from the underlying LLM, fine. For those businesses that are a layer above that, a bunch of resale abuse. So you literally sell it sometimes in other markets for a slightly discounted price, a discounted price on the base price that you should have paid but you didn't pay.
So there's a dark, like a dark web of marketplaces where you say, like, use Cursor or Lovable for $2, but my cost is zero, therefore I make money?
Yeah, exactly. So just say, I give you my login credentials, whatever. But then there's just this long tail—makes it sound small, but very domain-specific fraud pattern. So, for example, people steal tokens to create content that they then use to extract money in all sorts of scammy ways. So a simple example: we see people going in and mass-generating music tracks and then uploading them to Spotify and Apple Music and then getting fake streams and then collecting royalties.
Or then for basically all of the wrapper businesses, there's this whole other layer of wrapper on a wrapper where, rather than just resell the subscription on places like Taobao, they'll literally clone the AI company, right? You can just vibe-code a website. The backend is just spitting out exactly what you got from the service that you're stealing from. And then you sell the product as yours, but cheaper.
You gotta give it to people that they're creative. I mean, that sounds almost harder than starting an actual company.
Yeah, I don't know. I mean, they definitely put a lot of time into it. Tokens are also very valuable. And what's been interesting, as we sort of started seeing these trends maybe at this point six to nine months ago in various flavors, but then they escalated a bunch. Talking to AI companies, the large AI companies are all over this. It's one of the most existential things for their margins. They have been in the trenches with us identifying the issues.
They have been like, literally, we see a problem, we build a model: multi-account abuse. Okay, at the time of login, there's an API. You send us what you know, we send you back a score, you block if they're bad. At the time of free trial start, same thing. As people are accumulating usage, you send us all the metadata, we send you back whether they're fraud-y, and you can require a top-up or cut off service or whatever. Literally each of those, as we've seen them, we've, like, in the order of weeks gotten—generally this isn't even like a full-fledged product, it's like an API.
Like, you send us some stuff, we send you some stuff. And the adoption has just been like, okay, so the AI companies are all over this. I think what's interesting is every company is going to become an AI company. And I don't think the industry at large is thinking about this yet or has really even reasoned that, like, actually, most of the fraud that's happening is not traditional credential or payment fraud. It's like what we would historically have called first-party abuse, right?
Like resale abuse or account sharing or multi-accounting or free trials, like first-party abuse. And I think it wasn't that first-party abuse didn't happen before, it's just at least in sort of SaaS stuff, first-party abuse didn't cost you anything. And so, A, it wasn't that useful to get a little bit of Salesforce for free. The examples we talked about wouldn't be relevant in most SaaS. And B, even if it was useful to figure out a way to skim off the top, and you could get a little bit of profit for it as the fraudster, it didn't actually cost the business that much because their marginal cost was zero.
And so, as every business becomes an AI business, I think we've been, in the context of our work on Radar, really reasoning about our fraud prevention product as moving from transaction to full customer lifecycle and moving from traditional fraud to end-to-end abuse. But I don't think the whole industry is there yet. And you and I talked about much of the economic upside of AI, but I think that'll really only be realized if it can happen safely. So, for example, six to nine months ago, I was talking to some of these AI companies. They'd be like, oh, I know, I'm gonna solve my free trial abuse problem by cutting off free trials.
Like, I'm gonna solve my free trial abuse problem by only having a sales-led motion and only going after enterprises and not having PLG. And, like, I hear less of that today.
Not because the fraud's totally solved, but because everyone knows they need agents to also be their buyers. And if agents are going to be their buyers, they better have a self-serve motion. They better have a PLG motion. There's no way they want to siphon off that source of growth and sort of only double down on a highly secure sales-led motion. But it's been interesting to see what's happened with token theft. And I totally agree, the fraudsters are creative, but I think that's a manifestation of how valuable the tokens are.