A clandestine online service known as Poison Claude is offering discounted access to Anthropic’s premium AI models by exploiting fraudulently obtained cloud accounts and free credits. This operation highlights the growing gray market for AI services, particularly in regions where access is restricted or cost-prohibitive.
Poison Claude, accessible at poison-claude[.]bitsender[.]top, advertises “unlimited” tokens through various plans, charging only 5 to 15 percent of Anthropic’s official per-token rates. The service provides access to models such as Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6, accepting payments exclusively in cryptocurrencies like Tether, USD Coin, Ethereum, Litecoin, and Bitcoin to maintain user anonymity.
The operators accumulate multiple AI provider accounts, often leveraging sign-up bonuses like Amazon’s $100 AWS Bedrock credit, and route customer requests through accounts with remaining credits. Users receive an API key and instructions to redirect their Claude Code environment variables to Poison Claude’s servers instead of Anthropic’s official endpoint.
A configuration error exposed the operation’s scale, revealing 881 total users and 872 active users at the time of discovery. While the main domain is masked by Cloudflare’s CDN, a related endpoint, api.claudeopus.shop, was traced to a Hostinger server in Mumbai before the exposure was patched.
Similar services, such as Ecomagent[.]in, offer discounted access to AI models by exploiting cloud providers’ startup credit programs. Response metadata from Ecomagent’s API indicated the use of Google’s Vertex AI platform, suggesting that Anthropic models were being served through fraudulently obtained Google Cloud credits.
This pattern reflects a broader trend of automated account fraud in the AI industry. Okta Threat Intelligence reported over 105,000 fraudulent signup attempts against an AI video platform’s free trial, originating from 251 distinct IPs linked to VPNs and residential proxies concentrated in Lebanon, Indonesia, and Thailand. These patterns are consistent with users circumventing regional access restrictions.
In response, Anthropic has implemented Persona-based identity verification, requiring government ID and selfie checks for new accounts, and developed fingerprinting systems to detect abuse originating from specific time zones. Okta Threat Intelligence has notified Cloudflare, Anthropic, AWS, and Google Cloud about the documented infrastructure and abuse patterns and continues to monitor the evolving gray market for AI model access.
The emergence of services like Poison Claude underscores the challenges AI providers face in securing their platforms against fraudulent activities. As AI models become more integral to various industries, ensuring legitimate access and preventing exploitation through unauthorized channels will be crucial to maintaining the integrity and sustainability of AI services.