AI Security AI安全 4h ago Updated 1h ago 更新于 1小时前 48

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Poison Claude 出售折扣 Claude 访问权限,运营商可窥探每位客户提示词

Underground services like "Poison Claude" sell discounted access to Anthropic's LLMs by pooling fraudulently obtained free-tier accounts, charging users 5-15% of official per-token prices These proxy/gateway services give operators full visibility into customer prompts, creating serious privacy and data leakage risks Okta researchers identified at least six such services with hundreds of active users, exploiting free bonus credits (e.g., AWS Bedrock's $100 credit) through synthetic identity crea 地下网络犯罪论坛出现多个非法AI模型访问服务,Poison Claude等通过滥用AWS Bedrock免费积分提供折扣API访问 用户提示词经代理服务转发至官方模型,服务方可完全监控输入输出内容,存在严重隐私泄露风险 配置错误曾暴露API状态端点,显示881名注册用户中872人活跃,主域名通过Cloudflare CDN隐藏真实IP 类似灰色市场服务Ecomagent.in已服务近970用户,提供Anthropic和OpenAI模型折扣访问 滥用免费试用和 disposable domains 进行大规模合成身份创建,结合住宅代理绕过机器人检测

70
Hot 热度
65
Quality 质量
72
Impact 影响力

Analysis 深度分析

TL;DR

  • Underground services like "Poison Claude" sell discounted access to Anthropic's LLMs by pooling fraudulently obtained free-tier accounts, charging users 5-15% of official per-token prices
  • These proxy/gateway services give operators full visibility into customer prompts, creating serious privacy and data leakage risks
  • Okta researchers identified at least six such services with hundreds of active users, exploiting free bonus credits (e.g., AWS Bedrock's $100 credit) through synthetic identity creation at scale
  • Bad actors increasingly use disposable domains and residential proxies to evade bot detection, compounding the threat as AI agent deployments grow
  • The gray market for U.S. LLM access is expanding, particularly in China, where models are banned or blocked by the Great Firewall

Why It Matters

This reveals a growing underground economy that undermines AI model providers' security and billing models while exposing users to significant privacy risks. For AI practitioners, it highlights the dangers of using unauthorized API proxies and the importance of securing internal AI tooling configurations. The trend also signals escalating identity fraud and bot activity tied to AI agent proliferation.

Technical Details

  • Poison Claude operates as an API gateway proxy: customers receive an Anthropic-compatible API key and environment variable instructions to route requests through Poison Claude's infrastructure instead of directly to Anthropic, which then forwards prompts to pooled fraudulent accounts
  • The service exploits free-tier bonus credits (e.g., AWS Bedrock's $100 credit for new accounts) created at scale using disposable email domains such as dakaka.org, emailinbo.live, and ratixq.com
  • A misconfigured endpoint (api.claudeopus[.]shop/api/status) temporarily exposed user metrics showing 881 total and 872 active users before being patched
  • The primary domain (poison-claude.bitsender[.]top) is hidden behind Cloudflare CDN, while the API domain uses Cloudflare Turnstile for bot protection; Cloudflare added a phishing warning but declined to take down the API domain
  • A similar gray-market service, Ecomagent.in, claims ~970 users and offers discounted access to both Anthropic (Opus 4.8, Opus 4.6, Sonnet 4.6) and OpenAI (GPT Codex 5.5) models via a custom API endpoint
  • Residential proxies are increasingly used to mask malicious traffic behind benign consumer IPs, making detection and blocking significantly harder for providers

Industry Insight

  • AI model providers must treat API key abuse and synthetic identity creation as critical threats, investing in stronger identity verification, behavioral anomaly detection, and rate-limiting strategies tailored to AI workloads
  • Organizations using AI development tools (e.g., Claude Code) should audit their environment configurations and API endpoints to prevent accidental routing through unauthorized proxy services that could exfiltrate proprietary prompts
  • The rise of AI-driven bot networks and residential proxy abuse suggests a need for updated bot mitigation frameworks that account for AI agent traffic patterns, rather than relying solely on traditional web bot detection methods

TL;DR

  • 地下网络犯罪论坛出现多个非法AI模型访问服务,Poison Claude等通过滥用AWS Bedrock免费积分提供折扣API访问
  • 用户提示词经代理服务转发至官方模型,服务方可完全监控输入输出内容,存在严重隐私泄露风险
  • 配置错误曾暴露API状态端点,显示881名注册用户中872人活跃,主域名通过Cloudflare CDN隐藏真实IP
  • 类似灰色市场服务Ecomagent.in已服务近970用户,提供Anthropic和OpenAI模型折扣访问
  • 滥用免费试用和 disposable domains 进行大规模合成身份创建,结合住宅代理绕过机器人检测

为什么值得看

本文揭示了AI模型访问灰色市场的运作机制和安全风险,对AI开发者和企业用户具有重要警示意义。服务方作为API代理可完全监控用户提示词,这种隐私泄露风险在AI应用集成中常被忽视。

技术解析

  • Poison Claude通过收集AWS Bedrock账户的$100免费积分创建虚假账户池,用户支付加密货币后获得Anthropic兼容API密钥,提示词经其代理转发至官方模型
  • 服务网站明确说明用户请求被路由到池中的特定账户,收费仅为官方价格的5-15%,但服务方保留完整提示词可见性
  • 配置错误曾暴露/api/status端点,返回总用户881人、活跃用户872人的统计数据,主域名poison-claude.bitsender.top使用Cloudflare CDN隐藏源IP
  • 类似服务Ecomagent.in提供Anthropic Opus/Sonnet系列和OpenAI GPT Codex 5.5的折扣API访问,采用自定义API端点架构
  • 攻击者利用dakaka.org等一次性域名批量创建虚假账户,结合住宅代理网络使恶意流量伪装成正常用户IP

行业启示

  • AI模型提供商需加强账户创建验证机制,防止免费积分被规模化滥用,同时考虑API访问的隐私保护设计
  • 企业集成第三方AI服务时应评估代理层的数据可见性风险,对敏感业务场景优先选择官方直连渠道
  • 网络安全厂商需关注AI模型访问灰色市场的技术演进,特别是住宅代理与AI代理结合带来的检测挑战

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude LLM 大模型 Security 安全 Closed Source 闭源