YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0046

Incident record

Poison Claude resells Claude access through a proxy that reads every customer prompt

Severity
Medium
Status
In the wild
Type
Deepfake/Fraud
Target
Buyers of grey-market Anthropic Claude API access
Actor
criminal

What happened

Okta researchers identified a grey-market service called Poison Claude that resells access to Anthropic's Opus and Sonnet models at 5 to 15 per cent of the official per-token price, funded by fraudulently obtained cloud credit. Because customers route requests through the operator's own proxy API, the operator can read every prompt a customer sends; a configuration error briefly exposed a status endpoint showing 881 registered users, 872 of them active.

Okta identified a similar service, Ecomagent, offering discounted Anthropic and OpenAI access to fewer than 1,000 users, and linked the wider grey market to demand from China, where US frontier models are banned, blocked or not sold. Cloudflare placed a phishing warning on the main domain following disclosure, though as of 16 July 2026 it had declined to act on a second domain, claudeopus[.]shop. Okta said it notified Cloudflare, Anthropic, AWS and Google Cloud.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026