NewsStocksStripe Warns AI Companies of 'Token Theft' Fraud Risks Amid Rising Usage Costs

Stripe Warns AI Companies of 'Token Theft' Fraud Risks Amid Rising Usage Costs

Author: CryptoBriefing·

Key Takeaways

  • •Stripe has flagged "token theft" as a growing fraud scheme in which criminals open fake accounts, exhaust expensive API credits on usage-based AI billing, and disappear before payment is collected.
  • •Attempted multi-account abuse among AI subscription companies rose 40% in six months, with some industry segments experiencing spikes exceeding 600%, according to figures highlighted by Stripe.
  • •AI companies face fraud rates 4.3 times higher than the average startup, a figure that only drops to 2.6 times the norm even after countermeasures are implemented.
  • •AI voice generation company ElevenLabs reports blocking thousands of fraudulent accounts daily to keep losses manageable.
  • •Stripe updated its Radar fraud detection tool to intercept bad actors at the registration layer, blocking more than 3.3 million high-risk registrations for eight AI companies in a single month.
Stripe Warns AI Companies of 'Token Theft' Fraud Risks Amid Rising Usage Costs

Software once followed a straightforward economic formula: spend heavily to build, then spend almost nothing to serve each additional customer. Generative AI has upended that model. Every prompt, every generated image, and every agentic task costs real money to produce, and fraudsters have figured out how to make someone else pick up the tab.

Payments company Stripe is sounding the alarm on what it calls "token theft," a fraud tactic targeting AI companies' usage-based billing models, in which customers are charged for what they actually consume. Criminals create fake accounts, burn through expensive API tokens or credits, and vanish before anyone can collect payment.

The Scale of the Problem

AI subscription companies have recorded a 40% increase in attempted multi-account abuse in just six months, according to figures highlighted by Stripe. Some segments of the AI industry have seen those attempts spike by more than 600%.

At the transaction level, AI companies face fraud rates 4.3 times higher than the average startup. Even after implementing countermeasures, that figure only drops to 2.6 times the norm. Roughly one in six new customer signups in the AI sector is linked to token theft. The timing compounds the damage: because stolen usage is consumed in real time on the provider's own infrastructure, losses land before any payment can be collected, and there is no product to claw back afterward.

Stripe CEO Patrick Collison has described the trend as one of the most overlooked risks in the AI landscape. Automated agents, he notes, allow thieves to exhaust budgets at a pace that human fraud teams simply cannot match in real time.

Why AI Is Uniquely Vulnerable

Traditional software-as-a-service companies could afford to be generous with free trials, because the marginal cost of one additional user rounds to zero. AI companies operate under fundamentally different economics. Every query to a large language model burns compute, every image generation job consumes GPU cycles, and agentic workflow chains together multiple expensive inference calls.

Stolen AI credits also carry real resale value on secondary markets, where buyers can access premium AI capabilities at a fraction of the retail price — which is exactly what makes the free credits and trials AI companies extend to attract developers such a tempting target.

ElevenLabs, the AI voice generation company, has been on the front lines of this battle. The company reports blocking thousands of fraudulent accounts daily just to keep losses manageable.

Stripe's Response

Stripe has updated its Radar fraud detection tool specifically to address the token theft problem. Radar, the company's machine-learning-based fraud prevention suite used by businesses across its payments platform, blocked more than 3.3 million high-risk registrations for just eight AI companies in a single month.

The approach targets the registration layer rather than the payment layer. Token theft must be stopped before bad actors ever reach the product, because by the time they have used the service, the damage is already done. With attempted abuse still climbing industry-wide, how far registration-layer defenses like Radar's spread across AI companies — and what the fraud figures look like once they do — is one of the operational storylines to follow as usage-based AI billing matures.