Researchers have found online service Poison Claude reselling access to Anthropic’s premium AI models at a significant discount with suspicions that these discounts are coming from fraudulently registered cloud accounts filled with free bonus credits.
More details here: https://www.okta.com/blog/threat-intelligence/free_tokens_for_sale/
Dave Hayes, VP of Product at cybersecurity company FusionAuth, commented:
“The instinct is for Anthropic to hunt down the fake accounts and shut them off preemptively instead of waiting for the “customer” to contest the charge. You’ll mostly come up empty, because there’s no break-in to find. The account signed up, cleared the check, and spent its credits, exactly what it was authorized to do.
The real exploit is the gap between how little it takes to prove who you are and how much value that unlocks. A thin signup check is all that stands between someone and $100 to $350,000 in credits. The only lever that works is upstream.
Stop tying the credits to the signup, and make releasing the money a separate, deterministic decision sized to what’s at stake. Right now the resale price is the market telling you what that gap is worth: 5 to 15 cents on the dollar.”
There is a rush to do things with AI as quickly as possible. People really need to stop and think about it as not everything is golden when you look at it.
SOCRadar Discovers Infostealer “Kynx” Hunting for Wallets, Games, and AI Tools
Posted in Commentary with tags SOCRadar on August 8, 2026 by itnerdFollowing a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow.
Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.
What STRU Discovered:
Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.
The full report can be found here.
Leave a comment »