Your inference may already be getting resold — and your logs can still look normal.
If you run an inference API, gateway, or AI product and you’ve seen suspicious credential sharing, resale, or unexplained usage, DM me. I’m looking to talk to teams seeing this in production.
There is a growing reseller market built around stolen API keys, shared subscriptions, proxy access, account farms, and piggybacked sessions.
The scary part: much of it can look completely legitimate from the provider side.
Valid credential. Valid account. Normal-looking requests.
Meanwhile, the same access can be passed through brokers, resold across borders, or quietly used by someone the account owner has never heard of.
Most LLM security products focus on what an agent is doing.
The blind spot is who is actually behind the account.
That’s what we’re building at
@infertrail: behavioral detection for inference abuse, credential resale, and unauthorized access.
We’re publishing honeypot data, reseller-market research across Russian- and Chinese-language communities, attack patterns, and what we learn building detection for this problem.
Follow
@infertrail for the research.