Key Takeaways
- Anjney Midha projects token flows will reach $5 trillion in five years and $10 trillion in ten years, mirroring 1990s online payments.
- OpenRouter blocked 10 times more fraud volume month over month as bad actors shifted from stolen cards to reselling unauthorized inference traffic.
- Raw inference gateways face severe fraud risk, while vertical intelligence products with narrow scopes avoid most attacks.
- Stripe acquired OpenRouter to secure streaming token infrastructure against autonomous AI agents that run fraud at machine scale.
The Shift From Stolen Cards to Resold Compute
OpenRouter scaled past 10 trillion tokens per day, and the attacks followed immediately. Alex Atallah saw fraud dollar volume spike by 10x in a single month. The nature of these attacks evolved rapidly. Fraudsters started with standard stolen credit cards, then moved to laundering tokens by reselling inference against platform terms of service.
The economics explain the target. Token streams represent direct programmatic compute that converts into cash or free intelligence. Anjney Midha compares this phase to early web payments. In Midha's view, the token economy will grow to "$5 trillion" in five years and "$10 trillion" in ten years.
When billions of dollars flow through APIs every day, fraud detection becomes the barrier between a viable infrastructure platform and immediate insolvency.
Why Specialized AI Apps Dodge the Fraud Bullet
If you sell open-ended API access to raw LLM inference, you are building a lightning rod for automated abuse. Atallah draws a sharp line across business models: “If you're making a gateway or selling generalized inference you are a target for fraud. If you're selling very discreet intelligence products that are doing something pretty specific, then you're way less likely to get these fraudsters.”
Generalized gateways let an attacker extract raw compute to power anything. Discreet apps restrict inputs and outputs to a tight workflow, eliminating the attacker's margin on resale.
The threat will worsen as software agents replace human fraudsters. Midha points out that the current wave of human-driven scams will soon automate: “All the bad things that Alex described as being perpetuated by humans right now is going to be perpetuated by AI agents over the next 10 years.”
Fighting automated token fraud requires the same defense model Stripe built for credit card processing with Radar. That shared defense model drove Stripe to acquire OpenRouter, creating an infrastructure layer capable of filtering autonomous agent attacks before tokens ever leave the cluster.
What to Do With This
Audit your AI app's API exposure before scaling marketing. If you expose raw completions or broad system prompts that allow open-ended tasks, lock them down behind strict, single-purpose endpoints with per-user token quotas and rate limits. If users can use your credits to generate arbitrary text or code outside your core domain, add immediate card-verification checks at signup to stop traffic resellers before they drain your balance.