'Poison Claude' sold discounted Claude access that reportedly lets operator view user sessions

- Poison Claude advertised cut-rate access to Anthropic's Claude on August 5, while reports said the reseller's operator could read every customer prompt. - Okta researchers Jeremy Kirk and Mathew Woodyard said ads cited AWS Bedrock bonus credits, including a $100 signup credit, to explain prices. - Anthropic's terms and privacy materials remain available on its support and policy pages as scrutiny of third-party Claude access grows.

Poison Claude is the name attached to a gray-market service that advertised discounted access to Anthropic's Claude models while routing user activity through infrastructure controlled by the reseller, according to reports published on August 5. The Hacker News said the setup let the operator view customer prompts, creating a direct privacy risk for anyone using the service. Cybersecurity News separately reported that the low prices may have been subsidized with fraudulently created cloud accounts and promotional credits. ### How did the service reportedly work? The Hacker News reported on August 5 that Poison Claude was one of several services advertising unauthorized access to premium AI models on underground forums and messaging platforms. In that arrangement, users were not dealing directly with Anthropic. They were sending prompts through a middleman service that could inspect or log those requests before passing them on. (thehackernews.com) Okta researchers Jeremy Kirk and Mathew Woodyard said in an analysis cited by The Hacker News that advertisements for Poison Claude explained the cheap pricing by pointing to bonus credits on Amazon Bedrock accounts. The same analysis said those offers included examples such as a $100 AWS bonus credit, which the researchers said was used to justify discounted token sales. (thehackernews.com) ### Why is prompt visibility the central issue? Customer prompts are the core risk because prompts can contain source code, internal documents, credentials, business plans, legal drafts, or personal data. The Hacker News said the operator behind Poison Claude could see every customer prompt, meaning the discount came with the possibility that sensitive inputs were exposed to an unknown third party. (thehackernews.com) Anthropic's policy pages say Claude use is governed by consumer or commercial terms depending on the product surface, and the company distinguishes between direct Claude plans and API use through third parties such as Amazon Bedrock and Google Cloud Vertex AI. That distinction matters here because Poison Claude was described as an unofficial reseller, not an authorized access channel. (thehackernews.com) ### Where did the steep discounts reportedly come from? Cybersecurity News reported on August 5 that the service's pricing may have relied on fake accounts and free credits. The report described a model in which resellers obtain subsidized access through promotional programs or fraudulent account creation, then resell that access at prices far below official rates. The Hacker News, citing the Okta researchers, reported a similar mechanism involving cloud-provider credits tied to Bedrock accounts. (anthropic.com) That does not by itself establish the full funding chain for every transaction, but it does show that researchers traced the advertised discounts to credits and account structures outside normal retail purchasing. ### Is this just a pricing scam, or also a data-exposure problem? (cybersecuritynews.com) The reports describe both. The pricing side concerns whether access is being financed with abusive or fraudulent account creation. The data side concerns whether the reseller can capture everything users type. In practice, a buyer drawn in by lower prices could be accepting both risks at once: unreliable access and full prompt exposure. (thehackernews.com) Explainx.ai, in a separate July analysis of the broader token-resale market, described a wider ecosystem of pooled accounts, proxy APIs, payment fraud and model substitution around Claude and other AI tools. That broader reporting is consistent with the Poison Claude allegations, though the August 5 reports are the basis for the specific claims about prompt visibility and Bedrock credits. (thehackernews.com) ### What should readers watch next? August 5 is the key publication date for the Poison Claude reporting, and the most concrete next documents are the underlying threat-intelligence writeups and Anthropic's policy pages governing authorized access. Additional disclosures from Anthropic, Amazon Bedrock, Okta, or other security researchers would be the next named checkpoints if enforcement or takedown action follows. (thehackernews.com) (explainx.ai)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.