Discounted Claude access bought on the gray market may expose every prompt you send

More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI models, were discovered by Okta.

Okta believes the trend is likely driven by Chinese users seeking access to AI models that are unavailable because of regulatory and provider restrictions.

“The demand is driven by both cost and restrictions on access. It is being satisfied in a variety of ways, one of which is through fraudulent account registrations, often capitalizing on free trials or credits,” Okta said.

According to researchers, cost, access restrictions, and a degree of anonymity pull people toward these services. However, most are probably not familiar with the disadvantages.

“While the gray market offers some operational security over direct purchases, it cuts both ways,” Okta noted.

“When services are configured as a gateway proxy, the service provider has full visibility into prompts, as those prompts must be forwarded to a model. This is a privacy concern, as the service provider could accidentally leak or sell data,” they added.

Access can also disappear without notice, as AI companies tighten fraud controls and cut off the accounts these services depend on.

Poison Claude

One such site, Poison Claude, claims to offer access to four Anthropic models: Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.

AI model access fraud

Advertisements for Poison Claude (Source: Okta)

Advertisements for Poison Claude describe how the service keeps token prices low. According to the service’s website, it takes advantage of free bonus credits, such as the US$100 bonus credit for AWS Bedrock accounts. The operator says it adds those accounts to a shared pool, routes customer requests through a selected account, and charges between 5% and 15% of the official per-token price, depending on the model.

Poison Claude takes payment in several cryptocurrencies, including Tether, USD Coin, Ethereum, Litecoin, and Bitcoin. Once paid, the customer gets an API key for an Anthropic-compatible API, along with instructions for setting environment variables so their installation of Claude Code sends its traffic to Poison Claude’s servers instead of Anthropic’s.

“Prompts are passed from Poison Claude’s API to Anthropic, with the answers returned to the customer.”

A configuration mistake gave researchers a clue to how popular Poison Claude is. The service’s operators left an API route exposed, showing 881 total users and 872 active ones.

The main domain for Poison Claude, poison-claude.bitsender[.]top, ran behind Cloudflare’s CDN, hiding its originating IP address. Following responsible disclosure, Cloudflare, alerted about Poison Claude’s use of its CDN to hide the service’s origin, placed a phishing warning on the site, but had taken no action on claudeopus[.]shop even though that domain also runs behind Cloudflare.

Ecomagent

Ecomagent, a second service Okta identified, offers unlimited tokens for subscriptions below market price, with access advertised to Opus 4.8, Opus 4.6, Sonnet 4.6, and GPT Codex 5.5.

A sample API request posted on the service’s own website contained an ID field prefixed “msg_vrtx”, a signature specific to Google’s Vertex platform.

“Like Amazon, Google Cloud offers credit for new accounts, although users must register a billing payment card. Google also offers up to $350,000 in credits to AI startups that plan to use the Gemini Enterprise Agent Platform or its Gemini model,” Okta explained.

When Okta tested Ecomagent directly, the “msg_vrtx” signature did not appear in the response.

Like Poison Claude, Ecomagent left an unauthenticated API route exposed, showing total and active user counts, both under 1,000.

China-based users likely behind bulk of fake AI signups

Okta also tracked a separate wave of automated signup fraud hitting an AI video company’s free trial. Over about three years of log data, the company recorded more than 105,000 brute-force attempts from 251 distinct IP addresses tied to bot activity.

“Based on our data, we can say it is highly probable that China-based users are circumventing regional restrictions. Some of the top VPN providers, like QuickQ VPN, are commonly used by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China,” Okta wrote.

There are indications scammers are cashing in on this too. Access to the service was advertised on cybercriminal forums, where one seller, reached over Telegram, claimed to have both API keys and login credentials for sale, the credentials offering what they called “full access.”

A separate vendor charged $40 in Tether for a “created” account, arguing it beat a hacked one since stolen credentials get flagged and shut down faster. That seller handed over a username and password, promising the account would convert to a paid membership once the trial period ended.

“While a certain amount of fraudulent registration is an inevitable downside of offering free trials, it can be countered,” Okta concluded.

More about

Don't miss