SorosAhaverom reports that CrofAI shut down after allegations that it secretly resold OpenRouter inference using cheaper substitute models, potentially invalidating customers’ model-identity and pricing assumptions.
state: watchingheat: lowuncertainty: highknownscott: lowinference-routing provider-trust inference-economicsCrofAInahcrofOpenRouter
What is this?
CrofAI, which marketed itself as the 'cheapest inference provider in the world,' was exposed in a widely upvoted r/LocalLLaMA thread as allegedly a thin wrapper around OpenRouter that served customers cheaper substitute models under frontier labels at markups reported up to ~20x; the thread's author reports five endpoint probes in which responses still traced to OpenRouter with its fingerprints actively hidden. Per the account, operator nahcrof denied the allegations, backtracked, then deleted the shutdown announcement and wiped the service's entire online presence; LinkedIn and X posts amplified the story but are headline-level commentary adding no independent verification. A second, low-traction report against OneProvider claims self-run benchmarks show a capability gap inconsistent with its claimed 'claude-fable-5' endpoint, but it is unreplicated and of uncertain actor independence. Everything supplied traces to community testimony — no CrofAI-specific claim is independently verified, nothing in the material implicates OpenRouter itself, and for context legitimate resellers in this market discount OpenRouter rates only ~30-50%.
Why it matters to Scott
The OneProvider anecdote makes this a second instance of the same substitution pattern, but it instantiates what ip:concept.capability-audit already prescribes (vendor-neutral model-identity testing with exportable evidence) and touches nothing Scott runs — he routes via OpenRouter itself through LiteLLM, uses neither reseller, and nothing in the material implicates OpenRouter. Nothing new on either side since the last grounding (no verification, no extension of the claim, no consequential party newly arriving at his position), so this stays lineage under the reseller-risk and fingerprinting radar pages rather than news.
ip:concept.capability-auditdev:technology.openrouterradar:llm-api-reseller-dependency-risksradar:one-token-api-model-fingerprintingradar:moonshot-claude-routing-allegation
queries asked of Scott's wikis
- capability audit vendor-neutral model testing
- openrouter inference routing stack dependency
- model fingerprinting endpoint canary detection
- cheap inference reseller token margin economics
- exportable evidence eval harness
- local model fallback trust hedge
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p0momentum: steady2 platformsage 630h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p91 vs 1032 stories at the 336h mark (now 630h old) — ahead of google-ax-declarative-orchestration (1.0x), behind agent-context-privilege-escalation (1.0x)
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-09-24T12:42:58Z
grounded: known/low — The OneProvider anecdote makes this a second instance of the same substitution pattern, but it instantiates what ip:concept.capability-audit already prescribes
2026-09-24T12:36:26Z
The OneProvider attachment lifts this from a single unverified scam story to a second, self-benchmarked instance of frontier-label model substitution by cheap resellers — corroborating the pattern Scott already tracks, while leaving every CrofAI-specific claim (substitution, 20× markup, fraud) unproven. Heat stays low despite magnitude-valve eligibility: the top-decile multi-platform spread was the week-old CrofAI spike; current velocity is ~0 pts/h at the 10th percentile and the periphery is not expanding (the new post sits at 1 point).
2026-09-24T12:24:47Z
evidence attached: reddit.post.1woznrf — Independently benchmarked second instance of a reseller serving a substitute model under a frontier label, corroborating the model-identity substitution pattern.
2026-09-15T18:23:46Z
The discussion remains amplification of the original allegations; the new Discord screenshot link supplies no assessable contents or independent corroboration. Cool attention while retaining this as an unverified provider-trust incident, not a demonstrated reason to change Scott’s routing stack.
2026-09-15T10:25:24Z
grounded: known/low — The allegations illustrate Scott’s existing Capability Audit requirement for vendor-neutral testing and exportable evidence, and repeat the risk tracked in llm-
2026-09-15T10:22:32Z
case created — A reported shutdown following specific substitution allegations is a bounded provider-trust incident, distinct from the existing malicious-router and Moonshot cases, but remains unverified.
Decision trace
- 09-24 22:42repriceThe OneProvider attachment lifts this from a single unverified scam story to a second, self-benchmarked instance of frontier-label model substitution by cheap resellers — corroborating the pattern Sco
- 09-24 22:42groundThe OneProvider anecdote makes this a second instance of the same substitution pattern, but it instantiates what ip:concept.capability-audit already prescribes (vendor-neutral model-identity testing w
- 09-24 22:24attachIndependently benchmarked second instance of a reseller serving a substitute model under a frontier label, corroborating the model-identity substitution pattern.
- 09-24 22:23propose_attachIndependently benchmarked second instance of a reseller serving a substitute model under a frontier label, corroborating the model-identity substitution pattern.
- 09-17 01:41review_screenThe only addition is a joke comment, while removal of a comment linking to an unassessed screenshot does not add verified evidence or materially change confidence.
- 09-16 04:23repriceThe discussion remains amplification of the original allegations; the new Discord screenshot link supplies no assessable contents or independent corroboration. Cool attention while retaining this as a
- 09-16 04:23review_screenA new comment links to a purported screenshot of Discord activity, but the screenshot contents are not provided, so its evidentiary significance cannot be assessed; the deleted comment is immaterial.
- 09-16 04:20sensor_dirtycomment_update
- 09-15 21:23review_screenThe added comments are reactions and unverified restatements of the existing substitution and shutdown allegations, with no credible new evidence or implementation detail.
- 09-15 21:21sensor_dirtycomment_update
- 09-15 20:25groundThe allegations illustrate Scott’s existing Capability Audit requirement for vendor-neutral testing and exportable evidence, and repeat the risk tracked in llm-api-reseller-dependency-risks and one-to
- 09-15 20:22createA reported shutdown following specific substitution allegations is a bounded provider-trust incident, distinct from the existing malicious-router and Moonshot cases, but remains unverified.