Poison Claude Service Exploits Free Cloud Credits for Discounted AI Access
A gray market service named Poison Claude is selling heavily discounted access to Anthropic's AI models by exploiting fraudulently created cloud accounts and free credits from providers like AWS and Google Cloud.

A shadowy online service known as Poison Claude is offering access to Anthropic's premium AI models, including Claude Opus and Sonnet, at a fraction of the official price. Researchers from Okta Threat Intelligence have uncovered that this significant discount is achieved by leveraging fraudulently created cloud accounts, often provisioned with free credits from major providers such as Amazon Web Services (AWS) and Google Cloud.
This gray market operation caters to users who may find official pricing prohibitive or face geographical restrictions on accessing advanced AI tools. The service, hosted at poison-claude[.]bitsender[.]top, advertises "unlimited" tokens and bundled packages, charging customers only 5 to 15 percent of Anthropic's standard rates. Payment is exclusively accepted in cryptocurrencies like Tether, USD Coin, Ethereum, Litecoin, and Bitcoin, facilitating anonymity for both operators and users.
The operational model, as explained by the service itself, involves accumulating a pool of AI provider accounts. These accounts are typically opened using sign-up bonuses, such as AWS's $100 Bedrock credit. Customer requests are then routed through these accounts, prioritizing those that still have available credit. Once a user pays, they receive an API key and instructions to reroute their Claude Code environment variables to Poison Claude's servers instead of Anthropic's official endpoints.
An exposed status endpoint inadvertently revealed the scale of Poison Claude's operation, showing 881 total users and 872 active users at the time of discovery. While the main domain utilized Cloudflare's CDN for obfuscation, related infrastructure, specifically api.claudeopus.shop, was traced to a Hostinger server in Mumbai before the vulnerability was patched.
Poison Claude is not an isolated incident. A similar service, Ecomagent[.]in, has been observed offering discounted access to Anthropic and GPT models by exploiting Google Cloud's startup credit program, which can provide significant funding for AI development. Metadata from Ecomagent's API suggested that Anthropic models were being served through these fraudulently obtained Google Cloud credits.
These findings align with a broader trend of automated account fraud targeting the AI industry. Okta Threat Intelligence has also tracked a surge in fraudulent sign-up attempts against AI video platforms, with origins linked to VPNs and residential proxies in regions like Lebanon, Indonesia, and Thailand, often used to circumvent access restrictions.
In response to these emerging threats, Anthropic is implementing stricter identity verification measures, including government ID and selfie checks for new accounts, alongside enhanced abuse detection systems. Okta has notified relevant cloud providers and AI companies about the observed abuse patterns and continues to monitor the evolving landscape of AI access gray markets.
The exploitation of free cloud credits and fraudulent account creation represents a significant challenge for AI providers, highlighting the need for robust security measures that can keep pace with innovative abuse tactics. This trend underscores the growing importance of securing AI infrastructure and preventing its misuse for illicit gains.
This new report from The Hacker News details the operational mechanics of the Poison Claude service, including its use of free bonus credits from cloud providers like AWS to offer discounted AI model access. It also highlights a configuration error that briefly exposed an API status endpoint, revealing the service had nearly 900 users, and notes that Cloudflare has placed a phishing warning on the main domain while declining action on the API domain.