Skip to content

Build1 publisher3 min readPublished

Nomic's CEO alleges startups resell frontier traces generated on lab credits

Credits and rate-limit upgrades hand a startup one authorized account with high throughput. The fraud signals Anthropic described in February do not fire on it. The resale allegation itself is unverified.

The Engineer · Build desk

Illustration accompanying Nomic's CEO alleges startups resell frontier traces generated on lab credits

What happened

  • Mulyar also said founders of companies building reinforcement-learning environments were receiving substantial inbound interest from Chinese buyers.
  • Anthropic said on February 23rd that DeepSeek, Moonshot AI and MiniMax generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
  • OpenAI told a US House committee on February 12th that Chinese companies used unauthorized resellers and third-party routers to conceal where requests came from.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Environment builders now have to decide what they keep, because the prompts, tool calls and reward signals retained for debugging and replay are the same artifacts a distillation buyer would pay for.
  • precedent The cheapest correction available to a lab is contractual, so retention and redistribution clauses on credit-funded accounts are the likely next revision, and they would bind teams that never sold anything.
  • exposure Founders whose names sat in the screenshots carry the reputational cost of an unverified accusation, and any startup holding elevated access becomes a plausible suspect in it.
  • contradiction Both labs backed their own distillation claims with counts, attribution methods and a committee filing, while the September thread rests on what its author says he heard, so the two cannot be read at the same confidence.

A trace is a record of a model working a task: the prompt, the tool calls, the step-by-step reasoning and the grade someone put on the answer [10]. Distillation runs on exactly that, taking a stronger model's outputs to train or improve another one [10]. Companies that build reinforcement-learning environments hold the largest supply, because they write the tasks, the simulations and the scoring systems [11]. Epoch AI's survey of that market described those environments as a central input for frontier-model training, spanning coding, computer use and enterprise workflows [12]. The prompts, responses, tool calls and reward signals they generate become training material once someone retains them and transfers them [12].

Anthropic's February disclosure describes how it found the traffic it found. Proxy services assembled the account networks, mixed distillation requests into ordinary customer traffic and swapped in new accounts as old ones were banned [14]. Anthropic said it attributed the activity using request metadata, infrastructure indicators and information from industry partners [16]. The volumes it published work out to roughly 670 exchanges per account [18]. Moonshot AI's share was more than 3.4 million exchanges, about 21 percent of the total, including attempts to reconstruct Claude's reasoning traces [15][19].

Each of those signals depends on many accounts, thin volume in each, an intermediary in the request path [14][16]. A startup in one of the lab programs holds a single account and a rate-limit upgrade the lab granted it [8][9]. Anthropic could ban a fraudulent account as it found it [14]. It cannot do that with an account it upgraded on purpose.

Andriy Mulyar, founder and CEO of Nomic, wrote on September 14th that he had heard of "so many companies" using elevated model privileges to generate and resell traces during the past month [2]. The thread invoked Kimi, the model family from Moonshot AI, and Z.ai's GLM models [7]. Mulyar did not publish transaction records, datasets or buyer identities, and the thread does not establish that any OpenAI-, Anthropic- or Y Combinator-backed startup sold model output [4]. The screenshots he attached identified the accused founders and startups clearly enough that RuntimeWire cropped the names [5]. RuntimeWire reports that the three institutions were cited for their alleged connections to the startups and were not accused of authorizing any sale [6].

What a lab controls in this situation is the contract. OpenAI for Startups advertises free API credits, rate-limit upgrades and technical support for eligible companies in its investor network [8]. Anthropic's program offers credits and priority rate limits, with additional benefits for startups backed by partner investors and accelerators [9]. Both exist to recruit developers and help young companies absorb the cost of building on frontier models, and both create accounts able to produce larger volumes of output at lower effective prices [20]. The report does not describe any change to the terms of either program [21]. RuntimeWire's framing is that resale by recipients would turn those programs into a subsidy for rival-model training [22].

What to watch

  • Whether OpenAI or Anthropic adds output-retention or redistribution language to startup program terms.
  • Whether anyone publishes a transaction record, a dataset or a buyer identity behind the September 14th thread.
  • Whether the next enforcement disclosure from either lab covers accounts the lab itself authorized.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories