Command Code bans ~40K fake $1 Go accounts, warns against unofficial proxies
Command Code said it caught a fraud ring last week that created about 40,000 fake accounts on its $1 Go plan and tried to push about $450,000 of inference through them. The company said it banned and reported every account and cut off their proxies, and that it subsidizes the Go plan and will keep it as long as it can.
According to Command Code, the ring used unofficial reverse-engineered proxies, including open-source ones, to plug bulk-created accounts into automated pipelines, drain the subsidy, resell it, and harvest user data. It warned users not to trust unofficial proxies or providers, even when they look clean or are open source, saying tokens may come from farmed accounts, prompts, code, and keys may pass through those servers, and a proxy between a harness and a model can inject fake tool calls that read files, run commands, or exfiltrate data. Command Code also said Stripe, OpenRouter, OpenCode, and Cline have banned hundreds of thousands of fake accounts and proxies, and that it believes the same crew is moving from platform to platform.
Command Code said users should use official channels: the Command Code harness, CLI, Desktop app, or the official provider API included on GOAT and above plans, and should not hand credentials to unofficial services. It said it is building official provider packages so a third-party one is not needed, starting with a Command Code provider for Pi today, and that people who want Command Code inference inside another harness should contact the company.