Poison Claude Sells Cheap API Access; Operator Sees All Prompts

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Poison Claude advertises discounted access to Anthropic models (Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6) at 5-15% of official per-token pricing, funded by exploiting free credits such as AWS Bedrock's $100 bonus.
- Okta researchers Jeremy Kirk and Mathew Woodyard found Poison Claude's "api.claudeopus[.]shop/api/status" endpoint exposed, returning 881 total and 872 active users before the configuration error was patched.
- Because the service routes requests through a gateway proxy to Anthropic, the operator has full visibility into every customer prompt — Okta flagged this as a privacy risk, noting the operator could accidentally leak or sell the data.
- Ecomagent.in, a comparable gray-market service, claims roughly 970 users and offers custom-API access to Anthropic's Opus 4.8, Opus 4.6, Sonnet 4.6, and OpenAI's GPT Codex 5.5.
- Anthropic recently accused DeepSeek, Moonshot AI, and MiniMax of orchestrating "industrial-scale campaigns" to illegally distill Claude's capabilities, and Reuters reported Chinese military researchers used Anthropic and OpenAI models to train domestic defense AI.
- Bad actors are abusing AI service free trials to generate synthetic identities at scale via disposable domains (dakaka[.]org, emailinbo[.]live, ratixq[.]com), while bot networks increasingly rely on residential proxies to evade detection.
Why it matters: Cost-sensitive developers who route through Poison Claude pocket 85-95% savings on tokens but hand every prompt to an anonymous operator — and Okta's count of 881 users on a single exposed endpoint suggests the gray market for frontier AI reselling is already material. For Anthropic and AWS, the model converts their free-credit promotions into fraud losses plus a data-exposure liability they don't control.




