Poison Claude (hosted at poison-claude.bitsender.top) offers "unlimited" token plans and a la carte packages for four Anthropic models: Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 . The service operates as a proxy — customers point their Claude Code client or Anthropic-compatible API calls to Poison Claude's infrastructure rather than Anthropic's official endpoint .
The economics are straightforward: the operator creates large numbers of fraudulent or synthetic accounts on AWS and AI providers . Each new AWS account qualifies for promotional bonuses such as the $100 AWS Activate credit for startups . Poison Claude pools these credits across hundreds or thousands of accounts, routes customer requests through them, and charges customers 5–15% of the official per-token price — pocketing nearly pure profit .
As the service's own website states: "We add those accounts to our pool, your request is routed to a specific account under the hood (you don’t see this) and you get charged 5-15% of the official per-token price depending on the model" .
The discount comes at a steep cost. Because Poison Claude sits between the customer and Anthropic's API, it has full visibility into every prompt and response. This creates multiple risks:
Poison Claude is not an isolated operation. Okta's investigation uncovered more than half a dozen services on underground forums and messaging platforms offering discounted or "unlimited" token access to frontier AI models .
This gray-market ecosystem includes:
Okta's findings show these operations share a common playbook: abuse free trial credits and startup programs, create synthetic identities at scale, and route API calls through shared proxy infrastructure . The cloud providers' customer-acquisition incentives — designed to attract legitimate startups — have become a multi-million-dollar fraud pipeline.
For developers and enterprises tempted by heavily discounted API access, the message from security researchers is clear: there is no such thing as a free lunch in frontier AI access. Every prompt sent through a service like Poison Claude is a data liability — and the risks extend beyond individual privacy to potential corporate data leakage, intellectual property theft, and compliance violations.
The only way to ensure your prompts, your data, and your model outputs remain private is to use official, contractually governed API access from Anthropic directly.