In a concerning development, an elusive online service known as Poison Claude has been reported to offer access to Anthropic’s advanced AI models at significantly reduced prices. Investigations reveal that these discounts are primarily sourced from cloud accounts fraudulently created and stocked with complimentary credits.
The Rise of Gray Market AI Tools
As AI tools become indispensable for various technological tasks such as coding and research, a gray market has surfaced to provide budget-friendly access to these tools. This market particularly caters to users who are either unable to pay for official services or are restricted by regional barriers, including numerous users from China who face governmental limitations on U.S. AI models.
Okta Threat Intelligence has identified that Poison Claude, operated from the domain poison-claude[.]bitsender[.]top, openly markets “unlimited” AI tokens through plans that meter prompts and offer bundled token packages. Their service charges a mere 5 to 15 percent of Anthropic’s standard token rate due to the essentially free operational costs.
Cryptocurrency Payments and Account Fraud
To bypass identity verification, Poison Claude exclusively accepts cryptocurrency payments, including Tether, Bitcoin, and Ethereum. The service facilitates access to AI models such as Opus 4.8 and Sonnet 4.6 by pooling AI provider accounts. These accounts are often established using sign-up incentives like Amazon’s $100 AWS Bedrock credit, and customer requests are channeled through whichever account still has credits available.
Upon payment, users are provided with an API key and instructions to alter their Claude Code environment variables, redirecting them to Poison Claude’s servers instead of Anthropic’s official endpoints.
Implications and Industry Response
An error in configuration highlighted the operation’s scale, revealing 881 total users, with 872 being active at the time. Although the primary domain is safeguarded by Cloudflare’s CDN, a related endpoint was traced to a Hostinger server in Mumbai.
Poison Claude is not isolated in these activities. A similar service, Ecomagent[.]in, offers reduced-rate access to AI models by misusing Google Cloud’s startup credit program. This program can provide substantial credits to AI startups, which are then fraudulently utilized.
Okta Threat Intelligence has observed a broader trend of automated account fraud within the AI industry, tracking over 105,000 fraudulent account creation attempts from various global locations. This is in response to companies like Anthropic implementing stricter identity verification processes, which include government ID checks and selfie verification to curb abuse.
Efforts to counter these fraudulent practices continue as Okta Threat Intelligence informs major cloud providers, including Cloudflare and AWS, about the ongoing abuse, aiming to disrupt the evolving gray market for AI model access.
