Researchers have uncovered multiple underground services selling unauthorized access to Anthropic's Claude language models, with one operation called Poison Claude capturing particular attention.
Poison Claude advertises discounted access to several Claude variants, including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. The critical risk lies in the service's architecture. The operator maintains complete visibility into all customer prompts and interactions. Users believe they access Claude directly through legitimate API keys, but traffic routes through the operator's infrastructure, exposing every query, response, and sensitive data submitted.
This setup creates multiple attack vectors. Customers divulge business logic, proprietary information, personal data, and trade secrets in their prompts, all visible to the threat actor. The operator can harvest this intelligence for competitive advantage, blackmail, or resale. Anthropic's models also face abuse through the compromised access, potentially violating terms of service and enabling harmful activities like malware development or social engineering at scale.
The discovery of Poison Claude alongside other similar services reveals a growing market for unauthorized LLM access. Customers attracted by discounted pricing expose themselves and their organizations to severe operational and reputational risk. Any sensitive information submitted through these services is permanently compromised.
Anthropic has not disclosed whether Poison Claude uses stolen API credentials, account compromise, or other exploitation methods. The threat extends beyond individual users to enterprises relying on Claude for development, research, or customer-facing applications. Compromised prompts could leak competitive advantages, security vulnerabilities in development workflows, or proprietary algorithms.
Organizations should assume no data submitted through unauthorized Claude access remains confidential. The financial savings offered by such services evaporate against the cost of data exposure. Security teams should enforce strict policies limiting LLM access to official Anthropic channels and monitor for unauthorized integrations.
