Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that these savings are coming from an unexpected source: cloud accounts that have been fraudulently registered and filled with free bonus credits.

As frontier AI tools like Claude have become essential for coding, research, and vulnerability hunting, a thriving gray market has emerged to sell cut-rate access to users who either can’t afford official pricing or are blocked from it entirely, including many users in China facing government restrictions on U.S. AI models.

Okta Threat Intelligence discovered that Poison Claude, hosted at poison-claude[.]bitsender[.]top, openly advertises “unlimited” tokens through prompt-metered plans and bundled token packages.

Because the underlying usage is essentially free to the operator, customers are charged only 5 to 15 percent of Anthropic’s official per-token rate. The service offers access to Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6, and accepts payment exclusively in cryptocurrencies like Tether, USD Coin, Ethereum, Litecoin, and Bitcoin, which helps both operators and customers avoid identity verification.

The site’s own marketing explains the scheme in plain terms: operators accumulate a pool of AI provider accounts, often opened using sign-up bonuses such as Amazon’s $100 AWS Bedrock credit, then route customer requests through whichever account has credit remaining.

Poison Claude Selling Cheap AI Tokens

Once paid, users receive an API key and instructions to redirect their Claude Code environment variables to Poison Claude’s servers instead of Anthropic’s official endpoint.

A configuration error exposed just how popular the operation has become. An unauthenticated status endpoint revealed 881 total users and 872 active users at the time of discovery.

While the main domain hid behind Cloudflare’s CDN to mask its true origin, researchers traced a related endpoint, api.claudeopus.shop, to a Hostinger server in Mumbai before the exposure was patched.

Poison Claude isn’t alone. A similar service, Ecomagent[.]in, offers discounted access to Opus and Sonnet models alongside GPT Codex 5.5, reportedly by exploiting Google Cloud’s startup credit program, which can grant AI startups up to $350,000 toward the Gemini Enterprise Agent Platform.

Response metadata from Ecomagent’s API contained identifiers tied to Google’s Vertex AI platform, suggesting Anthropic models were being served through fraudulently obtained Google Cloud credits rather than direct Anthropic access.

These findings tie into a broader pattern of automated account fraud across the AI industry. Okta Threat Intelligence separately tracked over 105,000 fraudulent signup attempts against an AI video platform’s free trial, originating from 251 distinct IPs linked to VPNs and residential proxies concentrated in Lebanon, Indonesia, and Thailand, patterns consistent with users circumventing regional access restrictions.

Anthropic has responded by introducing Persona-based identity verification requiring government ID and selfie checks for some new accounts, while also building fingerprinting systems to detect abuse originating from Asian time zones.

Okta Threat Intelligence has notified Cloudflare, Anthropic, AWS, and Google Cloud about the infrastructure and abuse patterns documented, and continues monitoring the evolving gray market for AI model access.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.