If someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted?
It turns out that around 900 people were, and they may be regretting their decision.
Security researchers at Okta have shared details of Poison Claude, a service being advertised on cybercriminal forums that offers discounted access to Anthropic's AI capabilities.
Customers buy the cut-price access with cryptocurrency, and receive an API key with instructions on how to reconfigure their development tools to point at Poison Claude's servers rather than those belonging to Anthropic.
And what do they get in return? The same AI responses, but at between 5-15% of the normal official cost.
How Come It's So Much Cheaper?
The truth is that Poison Claude does not have a secret partnership with Anthropic, instead it takes advantage of Amazon's generosity.
Through a service called Bedrock, Amazon Web Services (AWS) hosts Anthropic's Claude models. New users are treated to a perk of US $200 in free credits.
Poison Claude takes advantage of the fact that there is nothing to technically stop someone from creating multiple fake accounts, using fraudulent identities, and disposable email addresses. Each one collects the US $200 credit bonus. A hundred fake accounts yields US $20,000 worth of free Claude access. A thousand yields US $200,000.
It's not as if Poison Claude even hides its methodology. On its website it declares:
"We add those accounts to our pool, your request is routed to a specific account under the hood (you don't see this), and you get charged 5-15% of the official per-token price."
A similar operation called Ecomagent runs an equivalent scheme, exploiting Google Cloud's offer to new sign-ups, through which Google offers qualifying AI startups up to US $350,000 in credits.
Every time one of Poison Claude's paying customers fires off a query, it gets silently billed against whichever fraudulent AWS account has remaining credits. When that account runs dry, the system moves to the next one.
Ok. So It Sounds Fraudulent, But that's Not My Problem, Right?
You need to remember this. Any AI prompts you enter via this service travel first to Poison Claude's servers, which then are forwarded to the real Claude, and then the answer is passed back. So Poison Claude can see exactly what you typed.
So everything you type, every question you ask, every piece of code you paste in, every document you share, is seen by Poison Claude.
And who knows what Poison Claude might they do with it. Maybe they will accidentally leak it, or sell it? Maybe they will harvest whatever useful business information, API keys, passwords, or sensitive personal data happens to float past their noses?
Remember, Poison Claude had no qualms about creating the fraudulent accounts to abuse Amazon's generosity. Can you feel confident that they will care about your privacy and security?
We already know that their security is less than perfect. Okta's researchers found an exposed API endpoint for Poison Claude which revealed it was running from a web hosting service in Mumbai, as well as some information about its paying customers.
Are Cut-Price AI Services a Threat to My Business?
Yes, you need to take steps now to prevent your staff from using unauthorized AI services - and they are more likely to choose ones offered for reduced prices than one that will be more difficult to justify on the company credit card.
Make sure to establish a clear policy on which AI tools your staff may use for work. It's essential to know where your data goes, and ensure that any AI service your business is using has proper data processing agreements.
And remind your staff that they should be as careful when using AI prompts as other communication tools. You (hopefully) have rules about what type of content can be sent via email, and you should have similar governance over the sharing of sensitive data with AI tools - particularly ones that have not been vetted by the IT security team.