Cybercrime Forums Are Selling Cut-Price Claude Access, and the Sellers Are Reading Every Prompt

Researchers found at least seven underground services offering stolen or resold access to commercial AI chatbots. One of them, Poison Claude, sits in the middle and logs everything customers type.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A dark web forum marketplace layout displayed on a monitor, with listings for AI chatbot access services visible, cryptocurrency payment options shown, and a lo
Share

Key points

  • Researchers found more than seven services on cybercrime forums selling illegal access to commercial AI models.
  • Poison Claude resells access to Anthropic's Claude models including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
  • Poison Claude's operator can read every prompt customers send, so stolen data or criminal plans typed there are visible to the seller.
  • These services undercut official pricing to attract users who want to skip identity checks or usage limits.
  • Buyers who paste in company secrets or victim data are handing that information to two strangers: the reseller and whoever buys the logs next.

A fresh crop of underground shops is selling discounted access to mainstream AI chatbots, and at least one is quietly recording every question its customers ask.

Security researchers counted more than seven such services advertised on criminal forums and messaging apps. The one drawing the most attention is called Poison Claude. It claims to sell cheap access to several Claude versions, the chatbot made by Anthropic.

What exactly is being sold here?

Access to expensive AI models at a discount, with no sign-up checks. Poison Claude advertises the Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 models, Anthropic's paid tiers normally sold through a company account or an API (a paid connection developers use to plug a chatbot into their own software).

The pitch is simple: pay the reseller, get a working connection, skip identity checks, pay less than you would on the official site. In practice, the seller is either using stolen API keys, abusing free trials at scale, or routing traffic through hijacked corporate accounts.

Why is this dangerous for the people buying it?

The middleman sees everything. A prompt sent to the official Claude app goes to Anthropic. A prompt sent to Poison Claude goes to the operator first, then on to Anthropic. Every pasted document, every draft phishing email lands in the reseller's logs.

The failure mode is obvious. Criminals buying this access to write scam emails or malware are handing their working notes to another criminal. If Poison Claude gets raided, or decides to sell its logs, every customer's activity is exposed.

Who gets hurt if the buyers aren't criminals?

Companies whose API keys were stolen in the first place. If a developer leaked an Anthropic key by committing it to a public repository, that key can be resold through a service like this and burned through until the bill arrives. One thing the post-mortem will say: nobody was watching the spend graph. We've covered how quietly that kind of reconnaissance can unfold, including how GitHub's own public tools can be used to map a company before attackers strike.

For context on how Anthropic has been managing access pressures, we reported in July that the company was already struggling with compute constraints on its top model. A grey market burning through stolen keys doesn't help.

Anthropic's standard response is to revoke compromised keys and rate-limit suspicious traffic, citing their usage policy. That's abuse containment. It's not a distribution fix.

Should you worry if you use AI at work?

Yes, but the fix is boring. Use the official app or your employer's approved version. Free or cheap access offered through a Telegram channel or forum post isn't a bargain. Somebody is paying, and if the price looks too low, your data is the payment.

Service Claims to resell Model versions named
Poison Claude Anthropic Claude Opus 4.8, 4.7, 4.6; Sonnet 4.6
Others (6+) Various commercial LLMs Not individually named

If your team isn't alerting on anomalous API key usage and geographic spread on your AI vendor bill, you're one leaked secret away from funding somebody else's crime spree.

© 2026 Threat Vectr