Poison Claude's business model rested on a simple but effective arbitrage: exploit the free promotional credits that cloud providers offer to attract new customers, pool those credits behind a shared proxy gateway, and resell the resulting compute at a fraction of the official price.
Credit farming: The operator created large numbers of synthetic (fake) accounts on AWS to claim free startup credits — such as the AWS Bedrock $100 bonus credit — and pooled those accounts together . This is often referred to as "free trial farming" and relies on automated scripts to generate thousands of email addresses and phone numbers .
Proxy gateway: Customer API requests were routed through a shared, opaque proxy layer that hid the underlying credential pool. Customers reconfigured their development environments to point to Poison Claude's custom API endpoint (e.g., api.claudeopus.shop) instead of Anthropic's real endpoint . The service itself was identified at poison-claude[.]bitsender[.]top .
Pricing: Tokens were resold at 5–15% of Anthropic's official per-token price (i.e., 70–90% off), and payment was taken in several cryptocurrencies . Some packages advertised "unlimited" requests within a token cap .
Because all customer requests passed through the operator's gateway before reaching AWS Bedrock, the operator could see, log, modify, or exfiltrate every prompt and every model response . HelpNetSecurity explicitly warned that "every prompt and response is exposed to the operator" .
Beyond prompt capture, the service offered no encryption-in-transit assurance, no data deletion policy, and no service-level agreement. Customers had no way to verify where their data was stored or forwarded . The risks extend further: stolen API credentials can be used for credential stuffing, account takeover, or "LLMjacking" — using stolen AI compute as attack infrastructure . Some gray-market proxies also silently swap requested models for cheaper alternatives and keep the price difference .
Poison Claude was not an isolated operation. Okta identified more than half a dozen illegal AI-access advertisements on underground forums, covering Anthropic, OpenAI, and Google Gemini models . A parallel service, Ecomagent, operated on the same model — fake accounts, free credits, discounted Anthropic/OpenAI access via custom API endpoints .
In China, an extensive network of proxy services — called "transfer stations" — operates openly on GitHub, Taobao, and Telegram, selling Claude access at 90% off using stolen accounts and undisclosed model swapping . Research published by the Oxford China Policy Lab documented these networks in detail . The supply side relies on synthetic identity fraud, bulk account creation, and stolen payment credentials to claim promotional offers, while the demand side comes from developers, startups, and actors in jurisdictions where official API access is restricted or too expensive .
Law enforcement has taken notice. Operation Bizarre Bazaar (December 2025–January 2026) was a documented operation targeting API credential theft rings . The Cloud Security Alliance has also published research on the "shadow relay market" for LLM API reselling .
Several U.S. policy developments at the federal level are relevant to this gray-market problem, though none directly address the specific fraud scheme employed by Poison Claude.
H.R. 8283 — the "Deterring American AI Model Export Act" (119th Congress) — aims to control access to closed-source frontier AI models, but its main focus is export controls rather than domestic gray-market reselling .
The White House Executive Order (June 2026) — "Promoting Advanced Artificial Intelligence Innovation and Security" — directs Treasury, NSA, and CISA to develop security frameworks for advanced AI, including information-sharing mechanisms for closed-source model owners . The EO asks AI developers to voluntarily submit certain cutting-edge models to federal agencies for review 30 days before public release .
CNBC reported on July 17, 2026, that the Trump administration is taking new steps to dictate which companies and entities are allowed access to frontier AI models from providers like Anthropic and OpenAI . And on August 4, 2026, the Wall Street Journal reported that new White House AI guidelines exempt U.S. open models from government review .
These regulatory efforts are primarily aimed at export controls and national security — preventing adversaries from accessing U.S. frontier models. The gray-market reselling problem (fake accounts, credit fraud, prompt interception) is largely a payment fraud and data privacy issue that current regulatory frameworks do not explicitly address, even though it directly undermines both the security and economic models those regulations seek to protect.