Okta found multiple underground services selling discounted or “unlimited” access to popular AI models by routing customer prompts through accounts created with free trials/credits. These services often work as proxy gateways, meaning the operator can see everything users type and may leak or sell that data. Okta also observed related signup fraud and the sale of API keys and login credentials on criminal forums and Telegram.
Key findings
- Okta identified “more than half a dozen services” advertised on underground forums and messaging platforms selling discounted/unlimited access to frontier AI models.
- Some services operate as gateway proxies, giving operators “full visibility into prompts,” creating confidentiality and data-leak risk.
- Poison Claude allegedly pools accounts created using free credits (e.g., “US$100 bonus credit for AWS Bedrock accounts”) and sells access for “between 5% and 15% of the official per-token price.”
- Customers are instructed to route Claude Code traffic to the proxy service by changing environment variables and using the proxy’s API key.
- Researchers found exposed API routes revealing usage: Poison Claude showed “881 total users and 872 active ones,” and another service showed user counts “both under 1,000.”
- Okta observed automated signup fraud against an AI video company’s free trial: “more than 105,000 brute-force attempts from 251 distinct IP addresses tied to bot activity.”
- On criminal forums/Telegram, sellers claimed to have “API keys and login credentials for sale,” including “full access,” and sold pre-created trial accounts paid in Tether.
Who’s being targeted
- Commonly targeted roles: Developers/Engineering, Data Science/AI teams, IT, Security, Procurement/Vendor management.
- Affected industries: Technology / AI model users, Software development teams, AI/ML users in any industry using confidential data in prompts.
- Attack channels: website, telegram.
- Impersonated: A third-party ‘Anthropic-compatible’ API provider offering cheap Claude tokens (e.g., ‘Poison Claude’), A ‘vendor’ on cybercriminal forums/Telegram selling access.
Awareness takeaways
- Do not enter sensitive company information into AI tools accessed through third-party ‘proxy’ gateways; treat them as untrusted and potentially monitored.
- Avoid ‘discounted’ or ‘unlimited’ AI access offers that require crypto payments or configuration changes to redirect traffic, these are high-risk and may violate policy.
- Train staff that buying ‘accounts/keys’ from Telegram or forums is a credential-theft and compliance risk, and access may be shut off without notice.
Red flags to watch for
- Requests payment in cryptocurrency for ‘discounted/unlimited’ access
- Instructions to route your AI tool traffic to a third-party server/proxy
- Claims of access via pooled free-trial/bonus-credit accounts
- Unsolicited access sold via Telegram/cybercriminal forums
- Payment requested in crypto (Tether)
- Selling ‘created’ accounts or credentials to bypass restrictions
Read the video transcript
See a site promising “unlimited Claude access for 5% of the price, pay in crypto”? That’s not a deal, that’s a data leak waiting to happen. Okta found gray‑market services like “Poison Claude” that pool free‑trial accounts, give you their API key, and tell you to point Claude Code at their proxy server instead of Anthropic’s. Here’s the catch: as a gateway proxy, they see everything you type. Your prompts, your code, even sensitive project details, operators can log it, leak it, or resell it. Okta even saw API keys and “full access” accounts sold on Telegram. If any AI deal wants crypto payment or makes you change API URLs or environment variables, stop and report it to security, never route company prompts through a third‑party Claude proxy.