OpenCode bans 8,000 stolen-card accounts | $80K/month scheme, subscription layer bears the loss
TL;DR
AI coding tool OpenCode banned 8,000 fraudulent accounts in one sweep — subscriptions bought with stolen credit cards and resold as API quota to downstream proxies. Theoretical cost $80K/month, but with a 30-60 day chargeback window, the subscription revenue is already consumed by compute cost before the fraud is noticed. Largest publicly disclosed sweep in 2026's AI subscription-layer fraud wave.
AI coding tool OpenCode banned 8,000 fraudulent accounts in a single sweep — the accounts used stolen credit cards ("black cards") to subscribe to OpenCode, then resold API quota to downstream proxy services. Theoretical cost for 8,000 accounts is $80,000/month, but stolen-card holders file chargebacks the moment they notice the unauthorized charge — the loss falls on OpenCode.
The black market logic is simple — AI subscription tools' API quota is valuable (Claude Code, Cursor, OpenCode cost $20–200/month for tens of millions of tokens). Proxy services aggregate these subscriptions and repackage the quota for users who can't pay directly (mainland China, Russia, North Korea). Proxies pocket the spread; the subscription layer eats the fraud loss.
The real leverage point is the 30-60 day chargeback window. In those 30-60 days: proxies sell the quota, downstream users burn through the tokens, and only then does the cardholder notice and file the chargeback. OpenCode's revenue is already gone to compute costs — Anthropic and OpenAI charge per token upfront-and-settle; refunded fraud can only be absorbed by the subscription layer.
This is 2026's textbook "subscription layer squeezed by fraud" case. Cursor banned a similar batch in May; Claude Code got its Anthropic Console subscription pipeline cut for a similar batch in June. 8,000 accounts and $80K is the biggest publicly disclosed sweep in this cycle.
Fraud won't stop — as long as AI tool pricing curves stay on "per seat" instead of "per token pass-through," proxies will keep spawning.
via landiannews
The black market logic is simple — AI subscription tools' API quota is valuable (Claude Code, Cursor, OpenCode cost $20–200/month for tens of millions of tokens). Proxy services aggregate these subscriptions and repackage the quota for users who can't pay directly (mainland China, Russia, North Korea). Proxies pocket the spread; the subscription layer eats the fraud loss.
The real leverage point is the 30-60 day chargeback window. In those 30-60 days: proxies sell the quota, downstream users burn through the tokens, and only then does the cardholder notice and file the chargeback. OpenCode's revenue is already gone to compute costs — Anthropic and OpenAI charge per token upfront-and-settle; refunded fraud can only be absorbed by the subscription layer.
This is 2026's textbook "subscription layer squeezed by fraud" case. Cursor banned a similar batch in May; Claude Code got its Anthropic Console subscription pipeline cut for a similar batch in June. 8,000 accounts and $80K is the biggest publicly disclosed sweep in this cycle.
Fraud won't stop — as long as AI tool pricing curves stay on "per seat" instead of "per token pass-through," proxies will keep spawning.
via landiannews