Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
Key Takeaways A clandestine online service, “Poison Claude,” is illicitly reselling access to Anthropic’s premium AI models at drastically reduced prices. The service reportedly...
Key Takeaways
- A clandestine online service, “Poison Claude,” is illicitly reselling access to Anthropic’s premium AI models at drastically reduced prices.
- The service reportedly leverages fraudulently registered cloud accounts loaded with free promotional credits, rather than legitimate purchases.
- Users pay a fraction of official rates for access to advanced models like Claude Opus and Sonnet, primarily using cryptocurrency, to bypass identity verification.
- Similar operations, such as Ecomagent[.]in, exploit free credit programs from major cloud providers like Google Cloud.
- Anthropic and cloud providers are implementing enhanced identity verification and abuse detection to counter this growing trend of AI account fraud.
Underground Market Leverages Free Credits for Discounted AI Access
An underground service known as Poison Claude is reportedly offering Anthropic’s advanced AI models at a steep discount, with researchers indicating that the low prices stem from the exploitation of fraudulently obtained cloud accounts and their associated free credits. This illicit operation capitalizes on the rising demand for sophisticated AI tools, particularly in regions where official access is either unaffordable or restricted.
Table Of Content
As advanced AI models like Anthropic’s Claude become indispensable for tasks ranging from software development to cybersecurity research, a shadow market has emerged. This market caters to users seeking cheaper alternatives or those in countries like China, where governmental restrictions often block access to U.S.-based AI services.
Poison Claude’s Modus Operandi
Okta Threat Intelligence has notified that Poison Claude, operating from poison-claude[.]bitsender[.]top, openly advertises “unlimited” AI tokens through various subscription and bundled packages. The service charges customers merely 5% to 15% of Anthropic’s official per-token rates because its underlying usage costs are essentially zero to the operator. Poison Claude provides access to models including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. All transactions are conducted exclusively in cryptocurrencies such as Tether, USD Coin, Ethereum, Litecoin, and Bitcoin, a method that allows both operators and users to circumvent identity verification processes.
The scheme is explicitly detailed in the service’s own marketing: operators amass a reservoir of AI provider accounts, frequently established using sign-up bonuses like Amazon’s $100 AWS Bedrock credit. Customer requests are then routed through any account that still possesses available credit.
Upon payment, users are issued an API key along with instructions to reconfigure their Claude Code environment variables to point to Poison Claude’s servers, rather than Anthropic’s legitimate endpoints.
Operational Scale and Infrastructure
The scale of Poison Claude’s operation was inadvertently exposed due to a configuration error. An unauthenticated status endpoint revealed a substantial user base, showing 881 total users and 872 active users at the time of discovery. While the primary domain leveraged Cloudflare’s CDN to conceal its true origin, researchers were able to trace a related endpoint, api.claudeopus.shop, to a Hostinger server located in Mumbai before the vulnerability was patched.
Broader AI Account Fraud Landscape
Poison Claude is not an isolated incident. A similar service, Ecomagent[.]in, also offers discounted access to Anthropic’s Opus and Sonnet models, in addition to GPT Codex 5.5. This service reportedly exploits Google Cloud’s startup credit program, which can grant AI startups up to $350,000 for platforms like the Gemini Enterprise Agent Platform. Response metadata from Ecomagent’s API contained identifiers linked to Google’s Vertex AI platform, suggesting that Anthropic models were being served via fraudulently obtained Google Cloud credits rather than direct access to Anthropic’s infrastructure.
These discoveries are part of a larger trend of automated account fraud impacting the AI industry. Okta Threat Intelligence has separately documented over 105,000 fraudulent signup attempts against a free trial for an AI video platform. These attempts originated from 251 distinct IP addresses associated with VPNs and residential proxies, predominantly located in Lebanon, Indonesia, and Thailand, indicating efforts to bypass regional access restrictions.
Industry Response and Mitigation
In response to these fraudulent activities, Anthropic has implemented enhanced identity verification measures. These include Persona-based checks requiring government-issued identification and selfie verification for some new accounts. The company is also developing sophisticated fingerprinting systems to detect and prevent abuse originating from Asian time zones.
Okta Threat Intelligence has proactively informed Cloudflare, Anthropic, AWS, and Google Cloud about the identified infrastructure and abuse patterns. The organization continues to monitor the evolving gray market for AI model access to mitigate future threats.
What You Should Do
- Organizations should educate employees about the risks of using unofficial or heavily discounted AI services, which may compromise data security and intellectual property.
- Implement strict policies against using non-sanctioned AI tools that operate outside of official vendor agreements.
- Monitor network traffic for unusual API endpoints or connections to known fraudulent AI service domains.
- For cloud providers, enhance fraud detection systems to identify and prevent the creation of accounts using stolen or fabricated identities and the abuse of free credit programs.
- Users should always opt for official channels when accessing AI models to ensure security, reliability, and compliance with terms of service.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.