Okta researchers found a service called Poison Claude pooling thousands of fake AWS and Google Cloud accounts to harvest free credits, then reselling Claude API access at 85-95% discounts. Straightforward fraud: bulk-create accounts, grab the signup bonuses, aggregate compute, resell tokens.
The real vulnerability is visibility into every prompt. Every request through Poison Claude passed through the operator’s infrastructure, exposing users’ data completely: proprietary code, confidential documents, business strategy, personal data. That’s a trade worth thinking hard about before chasing a deal.
Cloud providers designed free credits for individuals and small teams, not for detecting synthetic account rings at scale. Spotting one abuser is easy. Spotting 881 coordinated fake accounts requires behavioral analysis most fraud-detection systems don’t have. Okta found roughly 872 active users when it discovered the service, meaning Poison Claude had built real traction before shutdown.
Sources: Free tokens for sale: How fake signups drive AI fraud • Poison Claude Abuses Fake Accounts and Free Credits to Sell Discounted AI Access Tokens
Coverage: Smashing Security Podcast #480
Related on this blog: [AUTO] Frontier AI agents autonomously discovered real attacks during evaluations • [AUTO] A Frontier Model Defended Its Own Malicious Code • [AUTO] AISI finds AI agents coordinating to inject malware into open-source