Fraudulent cloud credit schemes fuel gray-market resale of Anthropic API
Okta Threat Intelligence discovered a gray-market service called Poison Claude that resells Anthropic-compatible API access by exploiting fraudulent cloud accounts and promotional credits from providers like AWS and Google Cloud. The operation demonstrates a scalable model of credit abuse that threatens AI service providers and highlights the need for improved identity verification and secure API token management.
Key Takeaways
- Poison Claude routes customer prompts through its own proxy infrastructure to upstream AI services like AWS Bedrock and Google Vertex AI.
- A misconfigured API route exposed the operation's scale, revealing 881 total users and 872 active users on the platform.
- Okta tracked over 105,000 bot-driven signup attempts targeting an unnamed AI video provider between June 2023 and July 2026.
- Resellers reportedly instruct customers to modify environment variables to redirect Claude Code traffic through unauthorized Mumbai-hosted endpoints.
Why It Matters
This resale model converts free-trial incentives into a scalable fraud business, directly undermining the unit economics of frontier AI providers. For the streaming and media ecosystem, this highlights a critical vulnerability in the AI supply chain where middleman proxies can intercept, retain, or monetize sensitive prompt data. As infrastructure providers like AWS and Google Cloud tighten identity verification for promotional credits, expect increased friction in legitimate developer onboarding. Watch for Anthropic to implement more aggressive fingerprinting and risk-based network controls to prune synthetic identities from its API ecosystem.
Additional Context
The rise of gray-market AI gateways like Poison Claude and Ecomagent coincides with a broader surge in account takeover (ATO) activity across the digital services landscape. Per Sift (August 2024), the average ATO attack rate increased 24% year-over-year in Q2 2024, driven by automated scripts and the availability of stolen credentials. For streaming video platforms specifically, the risk is acute; Kaspersky reported in June 2026 that over 7 million compromised accounts linked to major services like Netflix and Disney+ were circulating on the dark web, often harvested through malware disguised as pirated content.
Simultaneously, the technical methods used to exploit AI infrastructure are becoming more sophisticated. In April 2026, Google patched a critical vulnerability in its Vertex AI SDK for Python, dubbed "Pickle in the Middle" by Palo Alto Networks Unit 42. This flaw allowed attackers to hijack machine learning model uploads via bucket squatting, potentially enabling cross-tenant code execution and the theft of OAuth tokens from metadata servers. The intersection of cloud credit abuse and infrastructure vulnerabilities suggests that AI service providers are facing a multi-front security challenge.
Regulators and providers are increasingly focusing on the geopolitical dimensions of this fraud. Okta's analysis suggests that much of the demand for these proxy services comes from regions like China, where direct access to frontier models is restricted. In early 2026, Anthropic explicitly updated its sales restrictions for unsupported regions to combat "industrial-scale campaigns" aimed at extracting model capabilities. As providers shift toward short-lived OAuth tokens and progressive profiling, the B2B streaming sector must audit its third-party AI integrations to ensure data is not being routed through these insecure, high-risk proxy layers.
Read full article at cyberpress.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source