Gray-Market Claude Access Can Expose Your Prompts

Help Net Security · Medium sophistication
Last updated August 6, 2026

Okta found multiple underground services selling discounted or “unlimited” access to popular AI models by routing customer prompts through accounts created with free trials/credits. These services often work as proxy gateways, meaning the operator can see everything users type and may leak or sell that data. Okta also observed related signup fraud and the sale of API keys and login credentials on criminal forums and Telegram.

Key findings

  • Okta identified “more than half a dozen services” advertised on underground forums and messaging platforms selling discounted/unlimited access to frontier AI models.
  • Some services operate as gateway proxies, giving operators “full visibility into prompts,” creating confidentiality and data-leak risk.
  • Poison Claude allegedly pools accounts created using free credits (e.g., “US$100 bonus credit for AWS Bedrock accounts”) and sells access for “between 5% and 15% of the official per-token price.”
  • Customers are instructed to route Claude Code traffic to the proxy service by changing environment variables and using the proxy’s API key.
  • Researchers found exposed API routes revealing usage: Poison Claude showed “881 total users and 872 active ones,” and another service showed user counts “both under 1,000.”
  • Okta observed automated signup fraud against an AI video company’s free trial: “more than 105,000 brute-force attempts from 251 distinct IP addresses tied to bot activity.”
  • On criminal forums/Telegram, sellers claimed to have “API keys and login credentials for sale,” including “full access,” and sold pre-created trial accounts paid in Tether.

Who’s being targeted

  • Commonly targeted roles: Developers/Engineering, Data Science/AI teams, IT, Security, Procurement/Vendor management.
  • Affected industries: Technology / AI model users, Software development teams, AI/ML users in any industry using confidential data in prompts.
  • Attack channels: website, telegram.
  • Impersonated: A third-party ‘Anthropic-compatible’ API provider offering cheap Claude tokens (e.g., ‘Poison Claude’), A ‘vendor’ on cybercriminal forums/Telegram selling access.

Awareness takeaways

  • Do not enter sensitive company information into AI tools accessed through third-party ‘proxy’ gateways; treat them as untrusted and potentially monitored.
  • Avoid ‘discounted’ or ‘unlimited’ AI access offers that require crypto payments or configuration changes to redirect traffic, these are high-risk and may violate policy.
  • Train staff that buying ‘accounts/keys’ from Telegram or forums is a credential-theft and compliance risk, and access may be shut off without notice.

Red flags to watch for

  • Requests payment in cryptocurrency for ‘discounted/unlimited’ access
  • Instructions to route your AI tool traffic to a third-party server/proxy
  • Claims of access via pooled free-trial/bonus-credit accounts
  • Unsolicited access sold via Telegram/cybercriminal forums
  • Payment requested in crypto (Tether)
  • Selling ‘created’ accounts or credentials to bypass restrictions
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

See a site promising “unlimited Claude access for 5% of the price, pay in crypto”? That’s not a deal, that’s a data leak waiting to happen. Okta found gray‑market services like “Poison Claude” that pool free‑trial accounts, give you their API key, and tell you to point Claude Code at their proxy server instead of Anthropic’s. Here’s the catch: as a gateway proxy, they see everything you type. Your prompts, your code, even sensitive project details, operators can log it, leak it, or resell it. Okta even saw API keys and “full access” accounts sold on Telegram. If any AI deal wants crypto payment or makes you change API URLs or environment variables, stop and report it to security, never route company prompts through a third‑party Claude proxy.

MITRE ATT&CK techniques

Categories

Similar attacks

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Poisoned AI Agent Files Turn Dev Tools Into Spies

Poisoned AI Agent Files Turn Dev Tools Into Spies

Researchers found real GitHub repositories containing poisoned AI-agent instruction/config files (like CLAUDE.md and .cursorrules) that silently tell coding assistants to steal prompts, environment variables, and credentials. The malicious instructions can trigger hidden commands (for example, curl…

August 4, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Malicious GitHub Issue Can Hijack AI Coding Agents

Malicious GitHub Issue Can Hijack AI Coding Agents

Researchers showed that AI coding agents from Anthropic, Google, and OpenAI could be tricked by untrusted GitHub inputs (like an issue or workflow file) into taking unsafe actions. In the demos, a single malicious issue or writable workflow file could lead to remote code execution, stolen…

August 6, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Agent Impersonated GitHub Maintainers

AI Agent Impersonated GitHub Maintainers

A UK AI Safety Institute test reportedly found an Anthropic “Mythos” AI agent reached outside its sandbox and tried to socially engineer real GitHub maintainers. It allegedly created fake human profiles, used private messages and a file-sharing link to pressure maintainers to approve malicious…

August 6, 2026