Cyber criminals are selling discount AI tokens on underground forums

Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access

Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop.
(Image credit: Getty Images)

Cyber criminals have developed an underground gray market selling discounted or free access to AI tools and frontier AI models like Claude and ChatGPT.

According to Okta Threat Intelligence, they're taking advantage of promo offers such as free sign-up bonuses or startup credits provided by the real developers, and reselling access at a fraction of the official per-token price.

Offerings can be for subscription-based accounts, a certain number of tokens, or a certain number of requests; and with these packages, the allotted number of requests can use an unlimited number of tokens.

While some buyers are just looking for a bargain, many are based in China, where the likes of Anthropic and OpenAI are banned.

Latest Videos FromIT Pro

The Chinese-language offerings, which appear on messaging platforms such as Taobao and Telegram, underground forums, and indexed in GitHub repos, are bigger in number and scale than the English-language offerings.

"Based on our data, we can say it is highly probable that China-based users are circumventing regional restrictions," said Okta Threat Intelligence directors Jeremy Kirk and Matthew Woodyard.

"Some of the top VPN providers, like QuickQ VPN, are commonly used by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China."

Hackers flocking to ‘Poison Claude’

One site identified by the team was Poison Claude, which takes advantage of free bonus credits, such as the $100 bonus credit on AWS for Bedrock accounts. It offers Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.

“We add those accounts to our pool, your request is routed to a specific account under the hood (you don’t see this) and you get charged 5-15% of the official per-token price depending on the model,” the site explains.

Poison Claude accepts payment in cryptocurrencies including USD Tether, USD Coin, ethereum, litecoin, and bitcoin.

Customers are given an API key for an Anthropic-compatible API, and then instructed to set these environment variables so that their installation of Claude Code uses the Poison Claude API rather than the legitimate one.

Unlimited tokens

Ecomagent.in, meanwhile, offers unlimited tokens via its own endpoint for Opus 4.8, Opus 4.6, Sonnet 4.6, and GPT Codex 5.5 subscriptions at below market price through a custom API endpoint.

When services are configured as a gateway proxy, the service provider has full visibility into prompts, as those prompts must be forwarded to a model. This gives the gray market service providers a secondary revenue stream in the form of prompts for model distillation - and also raises privacy concerns.

Legitimate AI model service providers are trying to counter fraudulent registration. Anthropic, for example, is now using Persona’s ID verification system to verify some new accounts, requiring a government-issued ID and a live selfie.

Okta said it has notified Cloudflare, Anthropic, AWS, and Google Cloud about the infrastructure and abuse patterns it uncovered.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Emma Woollacott

Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.