By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Poison Claude Sells Discounted AI Access, Exposing User Prompts

Cybersecurity researchers have identified over six distinct services advertising unauthorized access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One prominent service, "Poison Claude," claims to provide access to Anthropic's large language models (LLMs), specifically mentioning versions like Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. These illicit offerings are being sold at significantly discounted prices compared to legitimate access, with some advertisements highlighting "lifetime access" for as little as $100, a stark contrast to the typical subscription fees for such advanced AI tools. The discovery was detailed in a report by cybersecurity firm Resecurity, which has been monitoring these clandestine marketplaces. The investigation revealed that the operator behind Poison Claude, identified by the handle "Poison," has been actively selling these compromised access credentials. Further analysis by the researchers indicated a severe security lapse: the operator of Poison Claude appears to have had visibility into every customer prompt submitted through their illicit service. This means that any sensitive information, proprietary data, or personal queries entered by users seeking discounted access to Anthropic's AI models were potentially exposed to the service operator. This situation presents a dual threat: it compromises the privacy and security of the users who are unknowingly interacting with a compromised AI service, and it also poses a risk to Anthropic's intellectual property and the integrity of its AI models if the operator were to misuse the observed interactions. The underground forums where these services are advertised are known hubs for illicit activities, including the sale of stolen credentials, malware, and other cybercrime-related tools and services. The presence of AI model access among these offerings underscores the evolving landscape of cyber threats, as malicious actors seek to monetize access to powerful AI technologies. Resecurity's report highlights the growing trend of threat actors exploiting vulnerabilities and misconfigurations to gain unauthorized access to AI services and then reselling that access on the dark web. The implications of such breaches extend beyond individual users, potentially impacting businesses that might inadvertently use compromised AI tools for sensitive operations. The researchers have not yet disclosed the specific technical methods used to gain access to these AI models, but the existence of such services points to potential vulnerabilities in how access credentials or API keys are managed or distributed, or perhaps through social engineering tactics targeting legitimate users. The exposure of customer prompts to the operator is a particularly alarming aspect, suggesting a deep level of compromise or a deliberate logging mechanism implemented by the illicit service. This incident serves as a critical reminder for users and organizations to exercise extreme caution when seeking or using AI services, especially those offered through unofficial or heavily discounted channels, and to ensure they are adhering to the terms of service and security best practices provided by the AI model developers.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.