{"id":2222,"date":"2026-08-05T16:42:46","date_gmt":"2026-08-05T16:42:46","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2222"},"modified":"2026-08-05T16:42:46","modified_gmt":"2026-08-05T16:42:46","slug":"poison-claude-sells-discounted-claude-access-while-its-operator-sees-every-customer-prompt","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2222","title":{"rendered":"Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 05, 2026<\/span><\/span><span class=\"p-tags\">AI Security \/ Threat Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhp3V9f5UsiH1E6dHfRvy0DEOYvcK14BatMbbLVfdPjLbu3PMInRmVXDi4xoGw-pSIuxUjZS1rdv4X7N1V9xRoV9RRVfaYdAWI6OTxKZzOhAlHYh6dKZNeAWCPkaPdGAvwgcOwFQ0atoRBUxKfE_KfhJpnm1yV1tXr5_Wv2yqND0vZCMMEfRB0V220SZbne\/s1700-e365\/ai-access.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.<\/p>\n<p>One such service, Poison Claude, claims to offer access to Anthropic&#8217;s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.<\/p>\n<p>\u00abAdvertisements for Poison Claude explain how the service can offer the cheap tokens: by taking advantage of free bonus credits, such as the US$100 bonus credit on AWS for Bedrock accounts,\u00bb Okta researchers Jeremy Kirk and Mathew Woodyard <a href=\"https:\/\/www.okta.com\/blog\/threat-intelligence\/free_tokens_for_sale\/\" target=\"_blank\">said<\/a> in an analysis published Tuesday.<\/p>\n<p>\u00abThe service plainly states on its website that: &#8216;We add those accounts to our pool, your request is routed to a specific account under the hood (you don&#8217;t see this), and you get charged 5-15% of the official per-token price depending on the model.'\u00bb<\/p>\n<p>Poison Claude accepts payments in cryptocurrencies. Once a customer completes a payment, they are provisioned an API key for an Anthropic-compatible API and instructed to set certain environment variables to ensure that their development environment (i.e, Claude Code) uses the Poison Claude API instead of Anthropic&#8217;s.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Prompts entered as inputs are then passed from Poison Claude&#8217;s API to Anthropic, with the answers eventually returned to the customer in the same fashion.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The identity security company said a configuration error exposed the API&#8217;s \u00abapi.claudeopus[.]shop\/api\/status\u00bb endpoint, querying which returns the number of total and active users as 881 and 872, respectively. The exposure has since been fixed.<\/p>\n<p>The main domain for Poison Claude, poison-claude.bitsender[.]top, is hosted behind Cloudflare&#8217;s CDN to conceal its originating IP address. Following responsible disclosure, Cloudflare has placed a phishing warning in front of the site, but appears to have \u00abdeclined to take action\u00bb on the API domain, which uses Cloudflare Turnstile for bot protection.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiVH8DnWdzJxIIqzS7lJJP_m9KmbR2cKwCW756fJqyfxa9zlpexxd5x5VqbgLdNL1u5AdWJZyif0h9CoQTkyZE8KIFn47ODe1exoRRV7pg1Wnm4cFHwHBj2EqN5YaZGRTrIwuX4mQ5T4yetxbO5pqOPa70x9dtyWpioGhRRqcNbM_n4-k2kpDNmqHfqnjfi\/s1700-e365\/okta.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiVH8DnWdzJxIIqzS7lJJP_m9KmbR2cKwCW756fJqyfxa9zlpexxd5x5VqbgLdNL1u5AdWJZyif0h9CoQTkyZE8KIFn47ODe1exoRRV7pg1Wnm4cFHwHBj2EqN5YaZGRTrIwuX4mQ5T4yetxbO5pqOPa70x9dtyWpioGhRRqcNbM_n4-k2kpDNmqHfqnjfi\/s1700-e365\/okta.png\" alt=\"\" border=\"0\" data-original-height=\"944\" data-original-width=\"1280\"\/><\/a><\/div>\n<p>A similar service that operates in the gray market is Ecomagent.in, which is estimated to have nearly 970 users and claims to offer discounted access to Anthropic&#8217;s Opus 4.8, Opus 4.6, Sonnet 4.6 and OpenAI&#8217;s GPT Codex 5.5 via a custom API endpoint.<\/p>\n<p>While there are many reasons why users may seek out such services offering AI model access, including cost, access restrictions, and some degree of privacy and anonymity, they also come with several inherent risks.<\/p>\n<p>Model providers may cut off access to fraudulent accounts, or service providers may lure customers with a frontier model but deliver a less expensive and less capable model.<\/p>\n<p>\u00abWhen services are configured as a gateway proxy, the service provider has full visibility into prompts, as those prompts must be forwarded to a model,\u00bb Okta said. \u00abThis is a privacy concern, as the service provider could accidentally leak or sell data.\u00bb<\/p>\n<p>The findings come amid a <a href=\"https:\/\/www.chinatalk.media\/p\/the-grey-market-for-american-llms\" target=\"_blank\">growing Chinese market<\/a> for U.S.-based LLMs that are either explicitly banned (as in the case of ChatGPT) or inaccessible in the country due to the Great Firewall. These services offer API relay or proxy platforms that allow local developers in China to access the models.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Earlier this year, Anthropic accused three Chinese firms, DeepSeek, Moonshot AI, and MiniMax, of orchestrating \u00abindustrial-scale campaigns\u00bb to illegally extract Claude&#8217;s capabilities to improve their own models. As recently as last week, Reuters reported that Chinese military researchers have used AI models developed by OpenAI and Anthropic to train domestic AI systems with an aim to advance their defense capabilities.<\/p>\n<p>What&#8217;s more, evidence shows that bad actors are abusing free trials offered by AI services to facilitate synthetic identity creation at scale using disposable domains like dakaka[.]org, emailinbo[.]live, and ratixq[.]com.<\/p>\n<p>\u00abBot activity is rising across the internet, particularly with the increasing deployments of AI agents,\u00bb Okta said. Those running bot networks also have more choice than ever with which to counter bot detection methods, such as residential proxies. Residential proxies allow malicious traffic to come from benign consumer IP connections with often little or no history of malicious activity, making it risky to block.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 05, 2026AI Security \/ Threat Intelligence Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2223,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,9,1295,2894,1765,2796,684,2895,2893],"class_list":["post-2222","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-claude","tag-customer","tag-discounted","tag-operator","tag-poison","tag-prompt","tag-sees","tag-sells"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2222"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2222\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2223"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}