Gray-Market Claude Access Can Expose Your Prompts

Help Net Security · Medium sophistication
Last updated August 6, 2026

Okta found multiple underground services selling discounted or “unlimited” access to popular AI models by routing customer prompts through accounts created with free trials/credits. These services often work as proxy gateways, meaning the operator can see everything users type and may leak or sell that data. Okta also observed related signup fraud and the sale of API keys and login credentials on criminal forums and Telegram.

Key findings

  • Okta identified “more than half a dozen services” advertised on underground forums and messaging platforms selling discounted/unlimited access to frontier AI models.
  • Some services operate as gateway proxies, giving operators “full visibility into prompts,” creating confidentiality and data-leak risk.
  • Poison Claude allegedly pools accounts created using free credits (e.g., “US$100 bonus credit for AWS Bedrock accounts”) and sells access for “between 5% and 15% of the official per-token price.”
  • Customers are instructed to route Claude Code traffic to the proxy service by changing environment variables and using the proxy’s API key.
  • Researchers found exposed API routes revealing usage: Poison Claude showed “881 total users and 872 active ones,” and another service showed user counts “both under 1,000.”
  • Okta observed automated signup fraud against an AI video company’s free trial: “more than 105,000 brute-force attempts from 251 distinct IP addresses tied to bot activity.”
  • On criminal forums/Telegram, sellers claimed to have “API keys and login credentials for sale,” including “full access,” and sold pre-created trial accounts paid in Tether.

Who’s being targeted

  • Commonly targeted roles: Developers/Engineering, Data Science/AI teams, IT, Security, Procurement/Vendor management.
  • Affected industries: Technology / AI model users, Software development teams, AI/ML users in any industry using confidential data in prompts.
  • Attack channels: website, telegram.
  • Impersonated: A third-party ‘Anthropic-compatible’ API provider offering cheap Claude tokens (e.g., ‘Poison Claude’), A ‘vendor’ on cybercriminal forums/Telegram selling access.

Awareness takeaways

  • Do not enter sensitive company information into AI tools accessed through third-party ‘proxy’ gateways; treat them as untrusted and potentially monitored.
  • Avoid ‘discounted’ or ‘unlimited’ AI access offers that require crypto payments or configuration changes to redirect traffic, these are high-risk and may violate policy.
  • Train staff that buying ‘accounts/keys’ from Telegram or forums is a credential-theft and compliance risk, and access may be shut off without notice.

Red flags to watch for

  • Requests payment in cryptocurrency for ‘discounted/unlimited’ access
  • Instructions to route your AI tool traffic to a third-party server/proxy
  • Claims of access via pooled free-trial/bonus-credit accounts
  • Unsolicited access sold via Telegram/cybercriminal forums
  • Payment requested in crypto (Tether)
  • Selling ‘created’ accounts or credentials to bypass restrictions
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

See a site promising “unlimited Claude access for 5% of the price, pay in crypto”? That’s not a deal, that’s a data leak waiting to happen. Okta found gray‑market services like “Poison Claude” that pool free‑trial accounts, give you their API key, and tell you to point Claude Code at their proxy server instead of Anthropic’s. Here’s the catch: as a gateway proxy, they see everything you type. Your prompts, your code, even sensitive project details, operators can log it, leak it, or resell it. Okta even saw API keys and “full access” accounts sold on Telegram. If any AI deal wants crypto payment or makes you change API URLs or environment variables, stop and report it to security, never route company prompts through a third‑party Claude proxy.

MITRE ATT&CK techniques

Categories

Similar attacks

Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Recruitment Emails Hide BitB Google/Facebook Traps

Recruitment Emails Hide BitB Google/Facebook Traps

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes…

August 17, 2026