Cybercriminals Are Reselling Claude and ChatGPT Access for 5-15% of Official Prices
Cybercriminals have built a thriving gray market selling discounted or free access to frontier AI models like Claude, exploiting promotional offers from legitimate providers and reselling them at a fraction of official prices. According to threat intelligence firm Okta, these underground services are particularly popular among users in China, where Anthropic and OpenAI are banned, raising concerns about both security and privacy.
How Are Criminals Reselling AI Model Access?
The underground market operates through multiple channels and pricing models. Cybercriminals take advantage of legitimate promotional offers, such as free sign-up bonuses or startup credits provided by AI companies themselves, then repackage and resell that access at dramatically reduced rates.
- Pricing Structure: Services charge 5-15% of the official per-token price depending on the model, with some offering unlimited tokens through custom API endpoints.
- Distribution Channels: These offerings appear on Chinese-language messaging platforms like Taobao and Telegram, underground forums, and indexed in GitHub repositories.
- Payment Methods: Operators accept multiple cryptocurrencies including USD Tether, USD Coin, Ethereum, Litecoin, and Bitcoin to maintain anonymity.
- Access Mechanism: Customers receive an API key for an Anthropic-compatible interface and are instructed to redirect their Claude installations to use the fraudulent service instead of the legitimate one.
Why Is China the Primary Market for Stolen AI Access?
The scale and sophistication of Chinese-language offerings far exceed English-language alternatives. Okta researchers Jeremy Kirk and Matthew Woodyard noted that the evidence strongly suggests circumvention of regional restrictions.
"Based on our data, we can say it is highly probable that China-based users are circumventing regional restrictions," the researchers stated, adding that top VPN providers like QuickQ VPN are commonly used by Chinese internet users, and the top email domain was qq.com, a popular email service in China.
Jeremy Kirk and Matthew Woodyard, Directors at Okta Threat Intelligence
One specific service identified by Okta, called Poison Claude, advertises access to multiple versions of Claude Opus and Sonnet models by pooling free AWS Bedrock credits worth $100 each. The site explains that customer requests are routed to specific accounts behind the scenes, with users charged only 5-15% of official pricing.
What Privacy and Security Risks Does This Create?
Beyond the obvious intellectual property concerns, these gray market services create a secondary revenue stream that raises serious privacy issues. When services operate as gateway proxies, the service provider gains full visibility into every prompt sent through their system. This means all user queries, conversations, and sensitive information must be forwarded to the underlying model, exposing them to potential data harvesting.
Okta identified at least two major services operating this way. Ecomagent.in, for example, offers unlimited tokens via its own endpoint for Opus 4.8, Opus 4.6, Sonnet 4.6, and GPT Codex 5.5 subscriptions at below-market prices. The prompts flowing through these proxies become valuable training data for model distillation, creating a hidden business model built on user data.
How Are AI Companies Fighting Back?
Legitimate AI providers are implementing stronger verification measures to prevent fraudulent account creation. Anthropic has begun using Persona's ID verification system for some new accounts, requiring users to provide a government-issued ID and submit a live selfie before gaining access.
Okta has notified major cloud and infrastructure providers about the abuse patterns it uncovered. The company reported its findings to Cloudflare, Anthropic, AWS, and Google Cloud, providing them with detailed information about the infrastructure and tactics used by these underground services.
The emergence of this gray market reflects the growing demand for frontier AI models globally, particularly in regions where access is restricted. As AI capabilities become more valuable and widely sought, the incentive for cybercriminals to exploit legitimate promotional systems will likely continue to grow, making stronger verification and monitoring essential for protecting both users and the integrity of AI services.