Executive Summary
Okta Threat Intelligence has identified a growing ecosystem of 'gray-market' AI access providers, most notably 'Poison Claude' and 'Ecomagent', that resell access to Anthropic and Google LLMs at 70-90% discounts. These services operate by fraudulently accumulating free cloud startup credits—such as AWS Bedrock or Google Vertex AI credits—through automated signup campaigns using synthetic identities and residential proxies.
Technically, these services function as adversarial-in-the-middle proxies. Users are instructed to modify local environment variables (e.g., for Claude Code) to point to the provider's API endpoint rather than legitimate service providers. This architecture gives the service operators full visibility into customer prompts and data, presenting a significant privacy and corporate espionage risk. Furthermore, the infrastructure relies on disposable email domains and a pool of illicitly registered accounts that are frequently rotated to evade provider detection.
The impact is two-fold: AI providers suffer from massive platform abuse and financial loss through credit theft, while corporate users of these discounted services risk exposing sensitive intellectual property and proprietary code to malicious proxy operators. High volumes of bot-driven registrations, often originating from residential IP space in Lebanon, Indonesia, and Thailand, highlight the industrialized nature of this fraud.
