logo

Discounted Claude access bought on the gray market may expose every prompt you send

ID: 1302f39f-26df-5cbd-9ff7-4925450b63c5

STIX ID: report--1302f39f-26df-5cbd-9ff7-4925450b63c5

Feed Name: Help Net Security

Threat Score
40/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Sinisa Markovic

...
...

Okta discovered multiple underground services offering discounted or “unlimited” access to AI models by abusing free credits and fraudulent account registrations; researchers found exposed API routes revealing user counts, evidence of mass automated signup attempts (over 105,000 brute-force attempts observed), and operational techniques like gateway proxying that expose prompts and data to service operators. The report highlights specific indicators (poison-claude.bitsender.top, claudeopus.shop, a "msg_vrtx" API signature), use of cryptocurrency payments, Cloudflare CDN obfuscation, and likely China-based users leveraging VPNs and bots to circumvent regional restrictions, warning of privacy risks and service instability as providers tighten fraud controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.