惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
V
V2EX
Jina AI
Jina AI
爱范儿
爱范儿
M
MIT News - Artificial intelligence
量子位
L
LangChain Blog
Google DeepMind News
Google DeepMind News
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
腾讯CDC
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss

OpenAI

Codex 多了个宠物功能,大家都有做啥有意思的宠物 只有我这么感觉吗? codex 5.5 比 cc 4.7 速度慢了 7-10 倍。。 求助: chatGPT 网络配置问题 切换 ChatGPT 从美区到土耳其有无风险? 大家现在都是用什么办法订阅 gpt pro 的? 准备买正价的 openapi pro 5x, apple 美国店 准备 100 刀的礼品卡 够不够? 或者 120 刀? Codex 5x 5 小时额度大概能用多少 Token 呢?想对比一下中转站和官方订阅 Codex 每个会话里的 Context 满了,自动压缩总是过不去 你们 Codex 弹电话验证了吗 我最近發現 chatgpt 可以綁 apple 年付的,我也是才知道 5.5 codex 模型是不是更耗流量了...... Codex 登录需要验证手机号了 chatgpt 代充这是常规操作 还是我被坑了 GPT pro 模型(5x plan)一周大约可以用几次? 哪个国家 appstore 订阅 openai pro 5x 价格最低? plus 怎么感觉越来越不经蹬了 强如 Codex GPT 5.5 竟也会犯如此低级错误 纯免费 GPT-Image-2 AI 生图服务:限时 无需任何登录 在不考虑封号风险的情况下, GPT-5.5 vs Opus 4.7 使用体验上哪个更好? chatgpt 充值求助 现在有什么稳定订阅 Chatgpt 的方法吗 慢讯 Free 计划用户继可以用 image-2 后,今天开始可以在 codex 内调用 GPT-5.5 Codex (APP) 保姆级全攻略,海量实战教程, 一文精通 关于 xiaomi MiMo Token Plan 的套路我一一说下 Codex 额度锁死 100%,这正常吗? 我做了一个 AI 电商生图工具: 13 场景预设 + 数据全在浏览器(1 毛 6 一张) Codex 最近的更新速度搭上火箭了吗? 有没有靠谱的 GPT Pro 代充站 我的 GPT 是猫,你呢 😄 Codex 额度又重置了 ?
[吃瓜] 有人在 Openai 论坛举报了谷歌英国 Plus 专业版计划被...
longxinglink · 2026-04-19 · via OpenAI

https://community.openai.com/t/google-uk-plus-pro-plan-is-being-widely-abused/1379242

To the OpenAI technical department

I am writing to formally report a serious and increasingly organized abuse of the ChatGPT Plus “first-month free trial” promotion, as well as the ChatGPT Pro subscription plan, both of which are currently being exploited through technical means in certain regions such as the United Kingdom and Japan. Based on sustained observation and analysis, certain unauthorized actors are leveraging advanced techniques to systematically intercept, manipulate, and resell promotional eligibility and subscription access at scale. This activity has evolved into a structured gray-market operation, posing significant risks to platform integrity, user security, and fair market competition.

  1. Technical Methods and Operational Workflow (Key Findings) The misconduct observed extends beyond simple account reselling and demonstrates a high degree of technical sophistication. The primary methods include:

Traffic Interception (Packet Capture) Unauthorized actors utilize packet capture tools to intercept and analyze network requests generated during the registration and activation processes of eligible users in designated regions (e.g., the UK and Japan). Through this process, critical parameters—such as subscription identifiers, regional markers, and promotional eligibility tokens—are extracted.

Credential Extraction and Reverse Engineering By analyzing API responses and validation logic, these actors identify key fields governing trial eligibility and subscription validation. This enables them to extract and reconstruct credentials in a transferable or reusable form.

Cross-Account Reuse and Credential Replay (“Rebinding”) The extracted eligibility credentials are reused or replayed across different accounts by modifying request parameters or reissuing intercepted requests. This allows promotions or subscription states—originally restricted to specific regions and user conditions—to be applied to other accounts, including those outside eligible regions or with prior subscription history.

Extension to Paid Subscription Abuse (ChatGPT Pro) In addition to the abuse of free trial eligibility, similar techniques are reportedly being applied to the ChatGPT Pro subscription plan. Unauthorized actors appear to exploit intercepted or manipulated subscription flows to provide access to Pro-level services at artificially low prices, further amplifying market distortion and platform risk.

Commercialization and Gray-Market Distribution These unlawfully obtained and reused trial entitlements and subscription accesses are subsequently packaged and sold through third-party platforms, social media channels, or private transactions at significantly discounted prices, forming a profit-driven gray-market ecosystem.

  1. Risk and Impact Assessment

This behavior introduces multiple layers of risk and adverse impact:

Violation of Platform Policies and Compliance Standards: These actions clearly bypass the intended constraints of both promotional offers and paid subscription models, undermining enforcement of terms such as regional eligibility, first-time use, and non-transferability.

Distortion of Market Pricing Structures: Artificially low resale prices disrupt both trial conversion funnels and standard subscription pricing (including Plus and Pro tiers), compromising fair competition and revenue integrity.

User Security and Privacy Risks: Users engaging in such transactions may be required to share account credentials or undergo abnormal procedures, exposing them to account compromise, data leakage, or potential suspension.

Increased Burden on Platform Risk Control Systems: Abnormal activation patterns and fraudulent subscription behaviors may strain detection systems and degrade overall service reliability.

Indication of Underlying System Vulnerabilities: The feasibility of such exploitation suggests potential weaknesses in eligibility binding, token validation, subscription state verification, and anti-replay protections.

  1. Recommended Technical and Administrative Measures

To mitigate and prevent further abuse, the following actions are recommended:

Strengthen Credential and Subscription Binding Mechanisms Bind trial eligibility and subscription states to multiple factors, including account ID, device fingerprint, payment profile, and geolocation data. Implement one-time-use tokens and stricter session validation.

Enhance API Security and Anti-Replay Protections Introduce robust request-signing mechanisms (e.g., dynamic signatures, timestamps, nonce validation) to prevent intercepted requests from being reused.

Reinforce Regional and Eligibility Verification Apply multi-layer verification for regional eligibility (IP address, billing information, Google account region, etc.), and flag anomalous cross-region activities.

Upgrade Anomaly Detection and Risk Control Systems Deploy advanced monitoring models to detect abnormal trial activation and subscription patterns, including high-frequency activations and cross-account irregularities.

Crack Down on Unauthorized Resale Channels Identify and penalize accounts and entities involved in resale activities, and collaborate with relevant platforms to remove illicit listings.

Improve User Awareness and Risk Communication Clearly inform users about the risks associated with purchasing services from unofficial channels.

  1. Formal Request for Action

In light of the above, I respectfully urge OpenAI to:

Conduct a comprehensive technical audit and security review of both trial and subscription systems (including Plus and Pro tiers);

Promptly identify and remediate any existing vulnerabilities;

Investigate and eliminate ongoing abuse activities at scale;

Enforce strict penalties against accounts and entities engaged in such misconduct;

Continuously enhance risk control mechanisms to prevent recurrence.

This issue not only threatens the stability of the platform’s commercial model but also directly impacts user trust and brand integrity. Swift and decisive action is essential to restore fairness, ensure compliance, and maintain a secure and transparent service environment.

Thank you for your attention to this matter. I am willing to provide additional technical details or supporting evidence if required.