Cybersecurity researchers have identified multiple illicit services advertising unauthorized access to artificial intelligence (AI) models on underground forums and messaging platforms. One prominent service, known as Poison Claude, claims to provide access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
Poison Claude operates by exploiting free bonus credits, such as the $100 bonus credit offered on AWS for Bedrock accounts. The service pools these accounts and routes user requests through them, charging customers only 5-15% of the official per-token price, depending on the model. Payments are accepted in cryptocurrencies, after which customers receive an API key compatible with Anthropic’s API. Users are instructed to configure their development environments to use Poison Claude’s API, effectively redirecting their prompts through the service.
A configuration error exposed the API’s status endpoint, revealing that Poison Claude had 881 total users, with 872 active at the time. This exposure has since been rectified. The main domain, poison-claude.bitsender[.]top, is hosted behind Cloudflare’s CDN to conceal its originating IP address. While Cloudflare has placed a phishing warning on the site following responsible disclosure, the API domain remains active and utilizes Cloudflare Turnstile for bot protection.
Another similar service, Ecomagent.in, reportedly has nearly 970 users and offers discounted access to Anthropic’s Opus 4.8, Opus 4.6, Sonnet 4.6, and OpenAI’s GPT Codex 5.5 via a custom API endpoint.
Users may be drawn to such services due to cost savings, access restrictions, or a desire for privacy and anonymity. However, these services pose significant risks. Model providers may terminate access to fraudulent accounts, and service providers might misrepresent the models they offer. Additionally, when services function as gateway proxies, they have full visibility into user prompts, raising privacy concerns about potential data leaks or misuse.
These developments occur amid a growing market in China for U.S.-based LLMs, which are either explicitly banned or inaccessible due to the Great Firewall. Services offering API relay or proxy platforms enable local developers in China to access these models. Earlier this year, Anthropic accused three Chinese firms of orchestrating large-scale campaigns to illegally extract Claude’s capabilities to enhance their own models. Furthermore, reports indicate that Chinese military researchers have utilized AI models developed by OpenAI and Anthropic to train domestic AI systems, aiming to advance their defense capabilities.
The emergence of services like Poison Claude underscores the challenges in regulating and securing AI model access. As AI becomes increasingly integral to various sectors, ensuring legitimate and secure access to these models is paramount. Users should exercise caution and prioritize official channels to mitigate risks associated with unauthorized services.