Cybersecurity experts have identified a concerning trend of unauthorized AI model access being sold on clandestine cybercrime platforms. Among these is a service named Poison Claude, which advertises access to Anthropic’s advanced language models like Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 at discounted rates.
How Poison Claude Operates
Poison Claude markets its services by exploiting free bonus credits, such as those available through AWS Bedrock, to offer cheaper token access. According to Okta researchers Jeremy Kirk and Mathew Woodyard, the service charges a fraction of the official token price, collecting payment in cryptocurrencies. Customers receive an API key compatible with Anthropic’s systems and configure their environments to use this key instead of the official one.
The service operates by routing user prompts through its own API, ultimately retrieving responses from Anthropic’s models. A recent security lapse revealed the API endpoint’s active user count, which has since been corrected. The main domain is obscured by Cloudflare’s CDN, although Cloudflare has issued a phishing warning for the site without addressing the API domain.
Risks and Implications
While services like Poison Claude and Ecomagent.in entice users with cost savings and privacy, they pose significant risks. Providers may terminate fraudulent accounts, and service operators can access all customer prompts, raising privacy concerns. Additionally, these services may not deliver the promised quality, offering outdated or less capable models instead.
The use of such services is particularly prevalent in China, where access to U.S.-developed LLMs is restricted. Chinese companies have been accused of harnessing these models to enhance their AI capabilities, and military researchers reportedly use them to bolster defense technologies. This underscores the global reach and potential impact of these illicit activities.
Emerging Trends and Concerns
There is a rising trend of exploiting AI services’ free trials for creating synthetic identities, employing temporary domains to bypass detection. This is part of a broader increase in bot activity, with attackers using residential proxies to mask malicious actions as benign traffic. The growing sophistication of such methods presents challenges for security professionals.
The findings draw attention to the need for heightened vigilance and improved security measures in AI technology deployment. As the market for unauthorized AI access expands, addressing these vulnerabilities becomes crucial to safeguarding data and maintaining the integrity of AI systems.
