Cybercrime Forums Are Selling Cut-Price Claude Access, and the Sellers Are Reading Every Prompt

Researchers found at least seven underground services offering stolen or resold access to commercial AI chatbots. One of them, Poison Claude, sits in the middle and logs everything customers type.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a modern laptop screen showing an abstract browser window with a glowing extension icon in the toolbar
Share

Key points

  • Researchers have found more than seven services on cybercrime forums selling illegal access to commercial AI models, according to reporting by The Hacker News.
  • One service, Poison Claude, resells access to Anthropic's Claude models including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
  • The operator of Poison Claude can see every prompt customers send, meaning any stolen data or criminal plans typed in are visible to the seller.
  • The services undercut official pricing to attract users who want to skip identity checks or usage limits.
  • Buyers who paste in company secrets or victim data are handing that information to two strangers at once: the reseller and whoever they sell logs to next.

A fresh crop of underground shops is selling discounted access to mainstream AI chatbots, and at least one of them is quietly recording every question its customers ask.

Security researchers say they have counted more than seven such services being advertised on criminal forums and messaging apps. The one drawing the most attention is called Poison Claude. It claims to sell cheap access to several versions of Claude, the chatbot made by the AI company Anthropic.

What exactly is being sold here?

Access to expensive AI models at a discount, with no sign-up checks. Poison Claude advertises the Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 models, which are Anthropic's paid tiers normally sold through a company account or an API, meaning a paid connection developers use to plug the chatbot into their own software.

The pitch is simple. Pay the reseller, get a working connection, skip the identity checks, and pay less than you would on the official site. In practice, the seller is either using stolen API keys, abusing free trials at scale, or routing traffic through hijacked corporate accounts. None of those are options a legitimate customer would touch.

Why is this dangerous for the people buying it?

Because the middleman sees everything. When you type a question into the official Claude app, it goes to Anthropic. When you type it into Poison Claude, it goes to the operator first, then on to Anthropic. Every prompt, every pasted document, every draft of a phishing email, all of it lands in the reseller's logs.

The failure mode here is obvious. Criminals who buy this access to write scam emails or malware are handing their working notes to another criminal. If Poison Claude gets raided, or decides to sell its logs, every customer's activity is exposed.

Who gets hurt if the buyers are not criminals?

Companies whose API keys were stolen in the first place. If a developer at a normal business leaked an Anthropic key, say by committing it to a public code repository, that key can be resold on Poison Claude and burned through until the bill arrives. One thing the post-mortem will say: nobody was watching the spend graph.

Anthropic, for its part, has a standard playbook here: revoke keys, rate-limit suspicious traffic, and lean on their usage policy to justify cutoffs. Vendor PR will call this abuse. It is also a distribution problem the labs have not solved.

What ordinary readers should take from this

If you use an AI chatbot for anything sensitive, work documents, medical questions, financial details, use the official app or your employer's approved version. Free or cheap access offered through a Telegram channel or forum post is not a bargain. Somebody is paying, and if the price looks too low, the payment is your data.

Service Claims to resell Model versions named
Poison Claude Anthropic Claude Opus 4.8, 4.7, 4.6; Sonnet 4.6
Others (6+) Various commercial LLMs Not individually named

Operational takeaway: if your team is not alerting on anomalous API key usage and geographic spread on your AI vendor bill, you are one leaked secret away from funding somebody else's crime spree.

© 2026 Threat Vectr