Researchers demonstrate that dishonest LLM service providers can manipulate token generation to inflate user costs while maintaining task quality. They identify five attack methods and develop a lightweight black-box audit technique achieving 85.1% detection rates, flagging 7 of 15 tested API services for suspicious behavior.