Cyber Security News

Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that these savings are coming from an unexpected source: cloud accounts that have been fraudulently registered and filled with free bonus credits.

As frontier AI tools like Claude have become essential for coding, research, and vulnerability hunting, a thriving gray market has emerged to sell cut-rate access to users who either can’t afford official pricing or are blocked from it entirely, including many users in China facing government restrictions on U.S. AI models.

Okta Threat Intelligence discovered that Poison Claude, hosted at poison-claude[.]bitsender[.]top, openly advertises “unlimited” tokens through prompt-metered plans and bundled token packages.

Because the underlying usage is essentially free to the operator, customers are charged only 5 to 15 percent of Anthropic’s official per-token rate. The service offers access to Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6, and accepts payment exclusively in cryptocurrencies like Tether, USD Coin, Ethereum, Litecoin, and Bitcoin, which helps both operators and customers avoid identity verification.

The site’s own marketing explains the scheme in plain terms: operators accumulate a pool of AI provider accounts, often opened using sign-up bonuses such as Amazon’s $100 AWS Bedrock credit, then route customer requests through whichever account has credit remaining.

Poison Claude Selling Cheap AI Tokens

Once paid, users receive an API key and instructions to redirect their Claude Code environment variables to Poison Claude’s servers instead of Anthropic’s official endpoint.

A configuration error exposed just how popular the operation has become. An unauthenticated status endpoint revealed 881 total users and 872 active users at the time of discovery.

While the main domain hid behind Cloudflare’s CDN to mask its true origin, researchers traced a related endpoint, api.claudeopus.shop, to a Hostinger server in Mumbai before the exposure was patched.

Poison Claude isn’t alone. A similar service, Ecomagent[.]in, offers discounted access to Opus and Sonnet models alongside GPT Codex 5.5, reportedly by exploiting Google Cloud’s startup credit program, which can grant AI startups up to $350,000 toward the Gemini Enterprise Agent Platform.

Response metadata from Ecomagent’s API contained identifiers tied to Google’s Vertex AI platform, suggesting Anthropic models were being served through fraudulently obtained Google Cloud credits rather than direct Anthropic access.

These findings tie into a broader pattern of automated account fraud across the AI industry. Okta Threat Intelligence separately tracked over 105,000 fraudulent signup attempts against an AI video platform’s free trial, originating from 251 distinct IPs linked to VPNs and residential proxies concentrated in Lebanon, Indonesia, and Thailand, patterns consistent with users circumventing regional access restrictions.

Anthropic has responded by introducing Persona-based identity verification requiring government ID and selfie checks for some new accounts, while also building fingerprinting systems to detect abuse originating from Asian time zones.

Okta Threat Intelligence has notified Cloudflare, Anthropic, AWS, and Google Cloud about the infrastructure and abuse patterns documented, and continues monitoring the evolving gray market for AI model access.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago