Cyber criminals are selling discount AI tokens on underground forums
Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access
Cyber criminals have developed an underground gray market selling discounted or free access to AI tools and frontier AI models like Claude and ChatGPT.
According to Okta Threat Intelligence, they're taking advantage of promo offers such as free sign-up bonuses or startup credits provided by the real developers, and reselling access at a fraction of the official per-token price.
Offerings can be for subscription-based accounts, a certain number of tokens, or a certain number of requests; and with these packages, the allotted number of requests can use an unlimited number of tokens.
While some buyers are just looking for a bargain, many are based in China, where the likes of Anthropic and OpenAI are banned.
The Chinese-language offerings, which appear on messaging platforms such as Taobao and Telegram, underground forums, and indexed in GitHub repos, are bigger in number and scale than the English-language offerings.
"Based on our data, we can say it is highly probable that China-based users are circumventing regional restrictions," said Okta Threat Intelligence directors Jeremy Kirk and Matthew Woodyard.
"Some of the top VPN providers, like QuickQ VPN, are commonly used by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Hackers flocking to ‘Poison Claude’
One site identified by the team was Poison Claude, which takes advantage of free bonus credits, such as the $100 bonus credit on AWS for Bedrock accounts. It offers Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
“We add those accounts to our pool, your request is routed to a specific account under the hood (you don’t see this) and you get charged 5-15% of the official per-token price depending on the model,” the site explains.
Poison Claude accepts payment in cryptocurrencies including USD Tether, USD Coin, ethereum, litecoin, and bitcoin.
Customers are given an API key for an Anthropic-compatible API, and then instructed to set these environment variables so that their installation of Claude Code uses the Poison Claude API rather than the legitimate one.
Unlimited tokens
Ecomagent.in, meanwhile, offers unlimited tokens via its own endpoint for Opus 4.8, Opus 4.6, Sonnet 4.6, and GPT Codex 5.5 subscriptions at below market price through a custom API endpoint.
When services are configured as a gateway proxy, the service provider has full visibility into prompts, as those prompts must be forwarded to a model. This gives the gray market service providers a secondary revenue stream in the form of prompts for model distillation - and also raises privacy concerns.
Legitimate AI model service providers are trying to counter fraudulent registration. Anthropic, for example, is now using Persona’s ID verification system to verify some new accounts, requiring a government-issued ID and a live selfie.
Okta said it has notified Cloudflare, Anthropic, AWS, and Google Cloud about the infrastructure and abuse patterns it uncovered.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Qualcomm appoints Wassim Chourbaji to lead EMEA operationsNews The long-serving Qualcomm executive succeeds Enrico Salvatori, who will retire next year after 25 years with the semiconductor giant
-
Thousands of npm packages compromised in ‘Chaindrop’ malware campaignNews The Chaindrop infostealer is a variant of the notorious Shai-Hulud malware strain
-
Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attackNews The AI library chief has called for investment to help “build powerful cyber defenses”, as alleged weaknesses in OpenAI’s monitoring emerge
-
An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’News The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts
-
1Password teams up with Anthropic to give Claude access to your credentialsNews A new ‘zero-exposure’ security framework allows agents to use stored credentials in the 1Password vault
-
The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious codeNews Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software
-
Flaws in some of the most popular AI coding tools left developers wide open to attackNews Malicious repositories can trick advanced AI agents into silently breaking out of their workspace sandboxes
-
OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'News The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware
-
‘These sorts of post-compromise techniques used to be restricted to actors with the technical knowledge to carry them out’: Anthropic warns AI is helping lower the bar for up-and-coming hackersNews AI is making it harder to differentiate between high and low-skilled actors