Okta Researchers Uncover Poison Claude Service That Sells Discounted AI Access and Reads All Prompts
This digest was compiled by AI from multiple sources — links to the originals are below.

Okta researchers Jeremy Kirk and Mathew Woodyard have discovered a service called Poison Claude that provides illegal discounted access to Anthropic's Claude language models by routing queries through fraudulently obtained AWS accounts. The service, which has 872 active users, charges 5–15% of the official token price and explicitly states it sees every user prompt. The discovery comes as similar services like Ecomagent.in also offer cut-rate access to AI models.
Poison Claude Operation
Poison Claude offers access to Anthropic's Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 models at 5–15% of the official per-token price. The service exploits free $100 AWS Bedrock bonus credits by adding fraudulently obtained accounts to a pool; customer requests are routed to a specific account without their knowledge. Payments are accepted in cryptocurrency, after which users receive an API key for an Anthropic-compatible endpoint and must set environment variables to redirect Claude Code requests through Poison Claude's proxy. This proxy invisibly forwards prompts to Anthropic and returns answers, while the operator retains full visibility of all traffic.
User Numbers and Configuration Leak
Okta researchers discovered a configuration error that exposed the API endpoint `api.claudeopus[.]shop/api/status`, revealing 881 total users and 872 active users. The exposure has since been fixed. The main domain, `poison-claude.bitsender[.]top`, is hosted behind Cloudflare’s CDN to hide its origin IP. Cloudflare added a phishing warning after responsible disclosure but declined to act on the API domain, which uses Cloudflare Turnstile for bot protection. A similar service, Ecomagent.in, claims nearly 970 users and offers discounted access to Anthropic and OpenAI models including GPT Codex 5.5.
Privacy Risks and Grey Market
Users seek such services for cost savings, access restrictions, or anonymity, but Okta warns of significant risks. Providers may lose access if accounts are terminated, or they may substitute cheaper models without disclosure. Because the service acts as a gateway proxy, the operator sees every prompt, creating a privacy risk of accidental leaks or data sales. The findings coincide with a growing Chinese grey market for U.S. AI models, reflecting the expanding demand for restricted technologies.
What's Next
Anthropic and AWS have not yet publicly responded to the findings, and it remains unclear whether they will take action against the fraudulent accounts. As grey-market AI services proliferate, regulators and model providers may face pressure to enforce access controls, but the technical challenge of detecting proxy-based abuse could leave such services operating for the foreseeable future.
1 source
Okta Researchers Uncover Poison Claude Service That Sells Discounted AI Access and Reads All Prompts






