Cybersecurity researchers at Okta have uncovered a network of underground services selling discounted access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. One such service, Poison Claude, advertises cheap tokens by exploiting free bonus credits, such as the $100 AWS Bedrock credit. The service routes customer prompts through its own API to Anthropic, giving the operator full visibility into every prompt, raising significant privacy concerns.
Okta discovered a configuration error that exposed Poison Claude’s API status endpoint, revealing 881 total users and 872 active users. The service, hosted behind Cloudflare’s CDN, has received a phishing warning from Cloudflare but remains operational. A similar gray-market service, Ecomagent.in, claims nearly 970 users and offers discounted access to Anthropic and OpenAI models.
These services pose risks including account cutoffs, model substitution, and data leakage. The findings also highlight a growing Chinese market for U.S.-based LLMs, with Chinese firms accused of extracting Claude’s capabilities. Additionally, bad actors are abusing free trials to create synthetic identities at scale, and bot activity is rising with the use of residential proxies to evade detection.
CVEs: CVE-2026-50522
Companies: Anthropic, Okta, Cloudflare, OpenAI, DeepSeek, Moonshot AI, MiniMax
Products: Claude, Opus 4.8, Opus 4.7, Opus 4.6, Sonnet 4.6, GPT Codex 5.5, AWS Bedrock
Service providers: Poison Claude, Ecomagent.in
Original source: thehackernews.com