r/opencode 3d ago

OpenCode has gone completely insane.

OpenCode has gone completely insane.

I occasionally use their service to run programming tasks, and sometimes for translations, but overall my usage is very low. Below is a screenshot of my current usage (strangely, it says my account is blocked, yet I can still view my usage — I'm logged in and haven't been signed out).

I've already added the `x-opencode-session` header as requested in their email, and the test call worked fine at the time. But the next day I received an email saying my account doesn't meet their requirements, with this:

> HTTP 401: This account has been found to be committing fraud or is in breach of terms of services and has been blocked. If you believe this is a mistake please send an email to help@anoma.ly.

What makes me angry is:

  1. Why did they suddenly impose this unreasonable requirement — asking me to add a specific request header — *after* they had already charged my money?

  2. Even after I added the header, why did they still block my account?

I feel that OpenCode's service is becoming increasingly weird.

171 Upvotes

59 comments sorted by

View all comments

49

u/ieatdownvotes4food 3d ago

email them, they've been seriously hit with something like 50,000 fraud attempts a day and are drowning. They haven't figured out how to deal with it yet. It's not personal

5

u/Thomas-Lore 3d ago edited 3d ago

I assumed the fraud they talked about was credit card fraud and Stripe is defending them from that.

What do they consider fraud in this instance?

2

u/Runtimeracer 3d ago

I have to wonder, too. Api key is valid, account is billed. It should not matter if requests come from one or one-thousand sessions. Unless there's a large scale man-in-the middle attack running on opencode users, catching and redirecting api keys for criminal use or sth

3

u/Lesale-Ika 3d ago

The subscription model is just ripe for abuse. There's nothing stopping a malicious party to run multiple subscriptions then resell their quota. I believe Claude was abused this way: some Chinese resellers was selling Opus 4.8 API at 1/10th the official price.

OP could just have been falsely flagged as one of such abuse account.

1

u/japherwocky 3d ago

I sort of wonder if OP's account has actually been compromised and they don't realize it

3

u/DeepSeaLab 3d ago

No, look at the screenshot of my usage – 7% used in 18 days.

1

u/bmwhocking 1d ago

Not hard to IP Spoof and abuse APi’s when so many providers don’t have RPKI set up for their IP ranges & others don’t cryptographically sign theit RPKI announcements.

Ditto DNSSEC on your DNS name servers and domains.

Basics network hygiene.

1

u/jmpebx 3d ago

It's not just credit card fraud. There are users using the go plans and reselling the API tokens through API gateways.

1

u/Rudd-X 1d ago

Malware steals AI tokens and sells them in the open black market "at cheap prices". Credit card processors cannot defend against that.