In February 2026, Anthropic disclosed that three AI labs had generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts.¹ Four months later it described a larger campaign: 28.8 million exchanges across about 25,000 accounts in six weeks.²
Most companies see a smaller, duller version of this where someone signs up, works through the free tier, and comes back under a new email when it runs out. The effects used to show up in extra support loads and skewed sales funnels but now infrastructure bears the brunt of the burden.
Stripe's CEO has reported that free trial abuse across its network has more than doubled in the last six months, and that 1 in 6 signups at some AI companies are involved in multi-account abuse. Those accounts are arranged at signup and consumed over the following weeks, so most teams find their version of it when the bill closes, late enough that the money is already spent.
Free trial abuse became a stored-value problem
Free trial abuse is the use of a product's free trial period by someone with no intention of converting, usually at scale, through repeat signups under fresh identities. While trial abuse is far from being a new fraud vector, leveraging it to steal AI tokens is new.
An AI token is the foundational unit of data that artificial intelligence uses to think, process language, and generate ideas. Tokens used to be viewed simply as technical building blocks for chatbots. They have since evolved into something much bigger, the foundational currency of agentic e-commerce. Automated business decisions now run on them. Machine intelligence has a price, and tokens are what pays it.
That price is why the account is a target. Stolen tokens produce work a buyer would otherwise pay for, or work they can resell at a margin, and the operation running the accounts is selling one or the other.
AI token fraud is free trial abuse aimed at the token balance itself, whether the target is trial credits, promotional grants, or prepaid API capacity. Fraudsters now target free trials to steal these valuable tokens, treating introductory offers like an open vault of digital cash. The attack can serve different vectors. One operation farms credits to use a product for free, another resells access into regions where a provider does not sell directly, while a third queries at volume to train a competing model. The signup looks identical in all three cases, which is what makes it hard to catch without the right signals.
An emerging threat: Distillation attacks
Distillation is the third payoff, and it is the one that does not show up as a cost of goods sold. Farming free credits and reselling access both end with someone extracting useful work from the model without paying. Distillation uses the stolen access differently.
In this case, the abuser sends millions of narrow, systematic queries designed to map how the model responds across a domain, then trains a smaller model on the answers. A frontier model may cost hundreds of millions of dollars to train at a top-tier lab but it costs nothing to copy when the queries are running on someone else's stolen credits.
Anthropic's September 2026 threat intelligence report shows how much leverage account-level fraud buys once it is inside. Covering misuse detected between December 2025 and August 2026, the report describes state-linked actors and others running accounts for cyber operations, surveillance, and attempted biological weapons research, alongside one case they described as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization." Anthropic caught it because they could see it from the inside. Most companies serving tokens have no equivalent view, which means a distillation campaign against them reads as a busy month.
The attack is a supply chain, and most of it happens out in the open before a dollar is spent
A token-draining operation moves through five stages. The first three, acquisition, entitlement, and provisioning, all happen before a single token is spent. Accounts get acquired, entitlements get claimed, and the infrastructure to run them in parallel gets provisioned. Each step leaves evidence. Most fraud tooling doesn't start looking until consumption, when the spend is already in the usage graph, and by the time an account gets shut down the operation has rotated into the next batch.
There are five stages to a token-draining attack:
Stage | What happens | Evidence left | Detectable before spend? |
Acquisition | Accounts sourced from synthetic identities, disposable email, compromised credentials, or bulk purchase | Email domain patterns, identity reuse, creation behavior | Yes |
Entitlement | Trial, promotional credit, startup/education program, or reseller access is claimed | Device and payment instrument overlap across accounts | Yes |
Coordination | Proxies, residential IP pools, cloud infrastructure, and rotating user agents are put in place so the accounts can run as one operation | Subnet clustering, signup bursts, automation signatures | Yes |
Consumption | The trial or token balance is actually used | None. Loss is already occurring | No |
Rotation | Banned accounts are replaced and traffic shifts across the cluster | None at the perimeter. Visible only in aggregate | No |
All five stages are actionable. Acting during the first three means the tokens never get spent. Acting during consumption means cutting the spend off partway through. Acting at rotation means catching the next batch at signup instead of after it drains."
Why identity-layer controls fail against account farms
Email verification, individual identity checks, and blocklists all assume the identity costs the attacker something. An operation buying identities in bulk treats each of those controls as a line item priced into the model.
None of this is new. Attackers have been farming fake accounts at scale for two decades, first against loyalty points and ad networks, now against tokens, so the fix hasn't changed either. No single identity check stops a funded operation, which is why the defense has to layer device, behavioral, and identity signals together instead of betting everything on one of them working.
Anthropic described the architecture as hydra clusters, sprawling networks with no single point of failure, where banning one account simply promotes the next.¹ That matches what most abuse operations look like once they mature, at any scale.
Deeper verification raises the price of an identity without taking it off the market. Anthropic began requiring a government photo ID and a live selfie from selected users in April 2026.⁴
Both checks already have workarounds in production. Forged documents and deepfaked liveness handle the automated version. There's also a manual version, where recruiters pay people in lower-income countries to sit for verification on someone else's behalf.⁵
Worldcoin's black market set the price years ago, with iris scans harvested in Cambodia and Kenya selling for under thirty dollars. Once an attribute can be re-bought, any control built on it becomes a cost of goods. That still has value at the top of a risk ladder, where the point is to make the next account expensive rather than impossible. It doesn't work as the thing standing between a farm and a free trial.
There's a touch of irony in the fact that the tokens being stolen fund the next theft. Compute farmed off one attack generates the synthetic documents, deepfaked selfies, and scripted signup behavior that build the next batch of identities, which get pointed back at the same trial offers. Every successful run lowers the cost of the one after it, essentially paying for itself.
Signals of Abuse Checklist
What to look for at signup:

The trial window is the exposure
Most SaaS fraud tooling screens at the payment event. That works when a card is required at signup, because the decision point and the access point are the same moment. The further those two drift apart, the more product gets consumed before anything gets checked.
A seven-day trial with no card required gives away a week of compute before the fraud stack is consulted. Products that deliberately never collect a payment method give away everything, indefinitely. Freemium tiers, usage-based onboarding, and self-serve AI features are all built this way on purpose, because the friction costs more conversion than the abuse costs margin. That tradeoff is defensible. It just leaves signup as the only place a decision can be made.
Trial structure | Payment method collected | First risk signal | Compute given away first |
7-day trial, card required | At signup | Signup | Minimal |
40-day trial, card at conversion (illustrative) | At conversion | Day 40 | 40 days |
Freemium, no payment method | Never | Never, if screening is payment-stage | Ongoing |
Post-paid usage-based | At signup, charged in arrears | Failed charge at cycle close | Full billing cycle |
Products that deliberately don't collect a payment method have no payment event to screen. Freemium tiers, usage-based onboarding, and self-serve AI features are all built this way on purpose, because the friction costs more conversion than the abuse costs margin. That tradeoff is defensible. It just leaves signup as the only place a decision can be made.
Trial cycling also exploits logic rather than identity. Account resets, referral loops between accounts one person controls, and credential sharing all extend access without ever tripping a payment check.
What survives account rotation
Some signals belong to the operation rather than to any one account.
The device. Account farms run on far fewer machines than accounts. A fingerprint built from device and browser attributes rather than a stored identifier doesn't break when cookies get cleared or the session goes incognito, which is what a farm reaches for first, and it persists through browser reinstalls and network switching. On mobile, a device wiped immediately before signup is a weak signal on its own, and several devices wiped in the same window is a much stronger one.
Behavioral biometrics. Typing cadence, copy-paste behavior, autofill patterns, and the absence of mouse movement describe how an account came into existence. Sardine's behavioral biometrics also track distraction events, where someone switches tabs or drops focus off the window mid-form, which is what a person reading stolen details off another screen tends to do. This fires at creation, before the trial starts, which makes it the one signal here that can prevent the loss instead of explaining it.
Graph network connections. One device across many accounts, one payment instrument across many organizations, one subnet across a signup burst. None of it is visible from inside a single session. Sardine's connections graph builds that view inside a company. Sonar extends it across the consortium as an anonymized device reputation flag on a give-to-get basis, so a device that generated fraud feedback at one company arrives already flagged at the next.
Programmatic access is a feature of most AI products, so bot traffic can't be treated as inherently suspicious the way it can at a checkout page. What matters is whether the automation is running on a path you offered.
These signals combine into a complete picture of who is actually behind the account, before the trial starts and before the money is spent. Get the full story behind every user.
Post-paid abuse
There's a version of this that happens after conversion. A customer signs up, provides a payment method, consumes thousands of dollars of tokens across a month, and never pays the invoice.
Nothing looks wrong while it's happening, because heavy consumption is the behavior a usage-based company is built to encourage. The signal that separates a good customer from an uncollectible one arrives when the charge fails, which is after the compute is spent. The exposure is closer to credit risk, and a decision made at signup doesn't settle it on its own.
The connection data carries over. An account sharing a device with three others that already charged back is a different proposition from one sharing nothing, and that comparison is available in the first week of the cycle rather than the fifth. Sardine supports decisions at multiple points, so an account can be re-scored as usage accumulates and while a top-up requirement or a capacity hold is still worth applying.
What no external vendor can see
Token velocity, prompt similarity, and capability-harvesting patterns all require telemetry only the model owner holds. No fraud platform outside your stack has access to any of it, and you should be skeptical of one that says otherwise.
Everything before the first API call is a perimeter problem. Account acquisition, entitlement, and the infrastructure that coordinates them leave evidence at signup, and that evidence is portable across companies. What happens inside your API is yours alone, and building detection there means building it yourself.
Neither half resolves much alone. A usage pattern that looks anomalous on its own becomes actionable once the account behind it shares a device with eleven others. A perimeter score that was borderline at signup gets settled by what the account does with the trial. Companies that catch this early are usually the ones where both sets of signals land in the same place.
Where to start
Most teams find this in the bill because they track cost per trial account and trial-to-paid conversion separately, and neither number looks alarming on its own. Putting them side by side usually resolves the picture fast.
The question worth taking to your next planning cycle is a narrow one: how many of your free-tier accounts share a device, and would you find out before or after the invoice?
The goal is not to add friction for everyone. It is to find the accounts that were never going to convert and stop them before the compute runs. Stop policy abuse without impacting legitimate customers.
How Sardine helps
Sardine is a risk platform built around the moment an account is created, which is where trial abuse gets decided and where payment-stage tooling has nothing to work with. The signals above run on products that never collect a payment method.
Zero-day signals mean a new pattern gets caught on first sighting, without waiting for labeled fraud data to accumulate. Nothing here stays the same long enough to label.
Scoring continues past the signup event. Signals can be sent at multiple points and decisions requested at the points that change the outcome. A low-risk signup that starts behaving like a farm mid-trial gets re-evaluated before the window closes, and the same mechanism covers a converted account whose collectibility changes during the billing cycle.
All of it decisions through a rules engine your team controls, which counts for a lot when the attack rotates faster than your release cycle.
Frequently asked questions
What is AI token fraud and how does it differ from traditional free trial abuse?
Traditional free trial abuse means someone signs up for a trial with no intention of paying, usually cycling through fresh email addresses to keep accessing the product for free. AI token fraud is the same behavior pointed at a metered product, where every session consumes real compute rather than just occupying a database slot. The financial exposure is fundamentally different because the loss scales with usage intensity rather than account count. One account that runs heavy agentic workloads can cost more than a hundred accounts sitting idle.
Why do payment-stage fraud tools miss free trial abuse on AI products?
Most fraud tooling is built around a payment event. If a product has a long trial before asking for a card, or never collects a payment method at all, the fraud stack has nothing to screen against until the damage is already done. A 40-day trial with card collection only at conversion gives away 40 days of compute before the first risk signal arrives. Freemium tiers and usage-based onboarding have no payment event by design, which means signup is the only point where a decision can be made.
What signals indicate free trial abuse at the account creation stage?
The strongest signals appear before the trial is ever used. Device fingerprint reuse across multiple accounts, typing cadence and copy-paste behavior during form completion, tab switching mid-form consistent with copying details off another screen, subnet clustering across a signup burst, and residential proxy traffic all leave evidence at signup. Behavioral signals are particularly valuable because they fire at account creation, before any compute is spent, making them the only signals that can prevent the loss rather than explain it after the fact.
How do account farms evade standard identity verification controls?
Account farms treat identity verification as a cost of goods rather than a barrier. Forged documents and deepfaked liveness checks handle automated verification. Manual workarounds involve paying people in lower-income countries to sit for verification on someone else's behalf, a practice with documented black market pricing going back to Worldcoin's iris scan harvesting cases in Cambodia and Kenya. Deeper verification raises the price of an identity without removing it from the market, which is why device and behavioral signals that survive account rotation are more durable controls than identity checks alone.
What is post-paid token fraud and why is it harder to catch than signup fraud?
Post-paid token fraud happens after a legitimate-looking account converts, consumes a large volume of tokens across a billing cycle, and then fails to pay the invoice. Nothing looks wrong during consumption because heavy usage is exactly the behavior a metered product is built to encourage. The signal that separates a good customer from an uncollectible one arrives when the charge fails, after the compute is already spent. Connection data helps close that gap earlier. An account sharing a device with others that have already charged back is a different risk proposition from one with no shared signals, and that comparison is available in the first week of the billing cycle rather than at invoice close.
Sources:
¹ Anthropic, "Detecting and preventing distillation attacks," February 23, 2026. https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks
² Patrick Collison on TBPN, May 2026. https://www.youtube.com/watch?v=T6ZRmi7Iwzc
³ Anthropic, identity verification requirements, April 2026, as reported by TechCrunch, June 22, 2026. https://techcrunch.com/2026/06/22/anthropic-says-claude-may-want-to-see-your-id/
⁴ Zilan Qian, "How to Buy Cheap Claude Tokens in China," ChinaTalk, May 5, 2026. https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in
⁵ Masha Borak, "Worldcoin may have a biometric data black market problem," Biometric Update, May 22, 2023. https://www.biometricupdate.com/202305/worldcoin-may-have-a-biometric-data-black-market-problem




