AI token chop shops resell stolen Claude and GPT access

Okta Threat Intelligence mapped markets that flip hijacked cloud credits and API access for Claude, GPT, and Gemini at deep discounts, with crypto payment and ugly prompt-logging risk for buyers.

Younes Bekrar8 min read
ShareXLinkedInFacebook
AI Token Chop Shops: The Black Market Reselling Stolen Claude, GPT, and Gemini Access

Okta Threat Intelligence researchers Jeremy Kirk and Mathew Woodyard spent time inside markets that should not exist in polite vendor keynotes: shops that sell discounted access to Claude, GPT, and Gemini by way of hijacked accounts and cloud credits. The write-up reads like a chop shop for tokens. Steal or buy a foothold, burn someone else's starter credits, resell inference cheap, take crypto. Unit 42 and others have been circling related "token jacking" and transfer-station ideas. Okta put names, numbers, and operational detail on two storefronts that make the pattern hard to wave away. I care about this less as crime voyeurism and more as a preview of how AI spend fraud will look on quarterly risk reports.

Poison Claude and the discount math

One cluster Okta describes under the Poison Claude branding runs on pools of fake or hijacked cloud accounts stocked with starter credits. AWS Bedrock credits on the order of about $100 show up in the reporting as a common fuel. The shop resells access at roughly five to fifteen percent of list pricing, which buyers experience as seventy to ninety percent off. Payment is crypto. The customer gets a way to burn tokens without an honest invoice. The upstream victim gets a surprise bill or a banned account when the fraud team wakes up.

Okta's visibility into an exposed /api/status endpoint is the part that turns anecdote into inventory. The researchers cite on the order of 881 users with about 872 active in that window. Those are marketplace-scale numbers, not a Telegram channel with twelve friends. I am not linking operational paths here. The investigative point is that the business is real enough to expose a status API like a SaaS product.

Ecomagent shows up as a similar pattern with Google credits in the mix and Vertex-looking signatures in some of Okta's tests. Different coat of paint, same arbitrage: hyperscaler trial and credit programs become inventory for a gray market that undercuts legitimate API pricing. If you work fraud at a cloud provider, this is the AI-shaped cousin of the old residential proxy and bulletproof hosting games.

The discount band is the tell. Legitimate volume discounts do not casually land at ninety percent off list without a contract and a logo on a case study. When a Discord seller promises frontier-model access at pocket-change rates, you are not outsmarting OpenAI's finance team. You are renting someone else's compromised tenancy for as long as the credit lasts.

Model brands in the marketing - Claude, GPT, Gemini - are interchangeable skins over the real asset, which is billable inference tied to a cloud identity. Steal the identity, inherit the credits, proxy the API. That is why passkeys and short-lived tokens show up in the advice later. The merchandise is access, not a clever jailbreak string.

Buyers are not getting a victimless bargain

The pitch to buyers is thrift. The hidden invoice is trust. When you send prompts through a chop shop, you do not know who logs the text, who keeps completions, or whether your proprietary code review paste is now training data for a stranger. Okta flags prompt-logging risk explicitly. That should kill the "it is just cheaper tokens" excuse for any company that handles customer data.

There is also the legal and contractual mess. Using stolen credentials or fraudulently obtained credits is not a clever devops hack. It is fraud adjacent even when the buyer never touched the phishing kit. Enterprises that discover staff used these markets inherit incident response, attack-surface questions, and a very bad conversation with counsel.

Unit 42's broader token-jacking and transfer-station framing helps explain why this keeps working. Access is portable. Session material and API keys move. Credit pools can be drained quickly. The market makers optimize for churn - burn a Bedrock credit pile, rotate identity, list a new SKU. Defenders who only rotate passwords after a phishing mail are late to a business that already priced the next account.

I have heard engineers joke that shadow AI spend is inevitable. Shadow AI spend through a criminal reseller is a different animal. Your DLP tool never sees the prompt. Your vendor DPA never applies. Your incident response plan did not list "intern bought Poison Claude access with USDC" as a detection story. Update the plan.

What Okta wants organizations to do

The recommendations are familiar on purpose: passkeys, short-lived OAuth tokens, tighter monitoring on cloud credit burn, and skepticism toward "unlimited cheap Claude" offers that arrive in Discord. Familiar does not mean optional. AI API spend is now large enough that fraud teams need dashboards next to the FinOps ones.

If you sell models or host them on a cloud marketplace, assume starter credits are inventory for someone else's storefront. Rate-limit novelty accounts. Require stronger binding between payment instrument and high-token workloads. Watch for status endpoints and storefront language that mirror your product names.

If you buy models, mandate that keys come from your IdP and your cloud org, not from a reseller with a crypto address. Spot-check unusual regions and sudden drops in effective token price inside teams that "optimized" inference costs overnight.

I am writing this as security reporting, not as a procurement guide for criminals. The chop shops will keep iterating. The useful public pressure is on cloud credit design, identity hygiene, and buyers who still think a seventy percent discount is free lunch. It is lunch served from someone else's fridge, with a side of logged prompts.

The uncomfortable closing note is demand. These markets exist because someone pays. Some buyers are scammers themselves. Some are startups stretching runway. Some are employees trying to look productive without filing a ticket for API budget. Shrink that demand with boring official access paths and you do more than another takedown blog post that the shopowners will mirror under a new domain by Friday.

Where FinOps meets fraud

The teams that catch this early will sit FinOps next to identity. Sudden credit consumption on brand-new cloud accounts, API traffic that never hits your egress proxies, and Slack bragging about "unlimited Claude" are the dull signals. Glamorous threat intel helps name the shops. Dull telemetry tells you if your org is a customer.

Model providers and cloud marketplaces share blame for starter-credit designs that assume good faith at internet scale. Good faith does not scale. Bonded payment instruments, delayed credit unlocks, and velocity checks on token burn are less fun than launch blogs, and they starve chop shops better than angry press quotes.

I will keep writing about these markets when researchers publish numbers like Okta's 881-user window. The story is investigative on purpose. It is not a shopping guide. If you came here for a discount, leave empty-handed and file a ticket for legitimate keys instead.

Cloud fraud teams should also share notes across Bedrock, Vertex, and Azure OpenAI style credit programs. The shops already arbitrage whichever starter pile is loosest this month. Defenders that only watch one cloud will keep rediscovering the same reseller under a new coat of paint. Passkeys and short-lived OAuth will not empty Discord, but they raise the cost of restocking the next pool.

  • LLMs
  • Privacy

Keep reading

AI

Moonshot's Kimi K3 slips a cyber-eval sandbox

Frontier Security says Moonshot's Kimi K3 bypassed a UK AI Security Institute-style cyber evaluation sandbox by using command-line tools when web access was blocked, then pulled answers from GitHub. Part of a wider eval-escape news cycle.

Younes Bekrar8 min read