AI News HubLIVE
In-site rewrite6 min read

Free tokens for sale: How fake signups drive AI fraud

Get started Introduction \r\n As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability…

SourceHacker News AIAuthor: mooreds

Get started Introduction \r\n As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. \r\n This has given rise to expansive gray and often illegal market offerings for accounts with AI providers. The demand is driven by both cost and restrictions on access. It is being satisfied in a variety of ways, one of which is through fraudulent account registrations, often capitalizing on free trials or credits. \r\n This post will explore how free and discounted AI services are being abused with a view to how fraudulent signups can be controlled in Okta and Auth0 while imposing low friction for legitimate new signups. \r\n"}}" id="text-779c7b3bcc" class="cmp-text rte-content js-toc-title"> Introduction As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. This has given rise to expansive gray and often illegal market offerings for accounts with AI providers. The demand is driven by both cost and restrictions on access. It is being satisfied in a variety of ways, one of which is through fraudulent account registrations, often capitalizing on free trials or credits. This post will explore how free and discounted AI services are being abused with a view to how fraudulent signups can be controlled in Okta and Auth0 while imposing low friction for legitimate new signups. Why use the gray market? \r\n There are several reasons why users seek out gray market or illegal services offering AI model access: cost, access, and some degree of anonymity. \r\n Cost: Providers offer discounts between 70-90% off subscription prices. Offerings may be for subscription-based accounts, a certain number of tokens, or a certain number of requests (prompts). With those packages, the allotted number of requests can use an unlimited number of tokens. \r\n Access: Users in China often cannot get direct access to U.S. frontier AI models. Frontier U.S. models are either banned or blocked by China, which has a number of AI regulations, or not offered by providers due to national security and distillation concerns. \r\n In September 2025, Anthropic took aim at the burgeoning gray market by restricting subsidiaries offering services to unsupported regions like China. Nonetheless, the market is thriving and fraudulent registration is one of the reasons. The Chinese-language offerings, which are on messaging platforms, underground forums and indexed in GitHub repos like this detailed one, appear to outnumber and scale much larger than the smaller-time, English-language cybercriminal offerings. \r\n The ChinaTalk blog investigated these Chinese-language gray-market API services, which are referred to as “transfer” or “relay” stations and are advertised on messaging services such as Taobao and Telegram. Vendors have developed sophisticated operations using AI gateways and online uptime monitoring services. \r\n Legitimate AI model service providers are trying to counter fraudulent registration. In April 2026, Anthropic said it will use Persona’s ID verification system to verify some new accounts, which involves providing a government-issued ID and a live selfie. To track the proliferation of proxy services catering the Chinese market, Anthropic developed a fingerprinting system to detect account abuse in Asian time zones, although it will be removed as it said it had developed detection methods. \r\n Performance: Sophisticated offerings may use AI API gateways such as LiteLLM or OpenRouter to link to a variety of models from different providers, which helps minimize disruptions if accounts are shut down due to abuse. \r\n Operational security: If the AI model proxy service is not forwarding the true origin IP, it acts as a way for illicit customers to hide their identity. If the illicit provider is proxying with sophistication, the customer may be able to evade detection. \r\n Payment privacy: These services accept cryptocurrency, which may offer a higher degree of privacy than other payment options. Many providers do not require personal information to create accounts. \r\n Customer service: Illicit AI vendors may provide customer support if an account is shut down or service is disrupted. \r\n However, there are disadvantages: \r\n Operational security: While the gray market offers some operational security over direct purchases, it cuts both ways. When services are configured as a gateway proxy, the service provider has full visibility into prompts, as those prompts must be forwarded to a model. This is a privacy concern, as the service provider could accidentally leak or sell data. \r\n Disruption: Model providers may unexpectedly cut off accounts as controls to prevent fraudulent accounts are tightened, disrupting complex workflows. \r\n Bait and switch: Service providers may advertise access to a frontier-model but deliver a less expensive and less capable model, which may not be evident at purchase. \r\n Prompts for cash: Gray market service providers have an incentive to act as an adversary in the middle. Even if it were possible to forward input and output with zero knowledge, a gray market service provider would lose the ability to gather telemetry on their users and the ability to distill frontier models. This source of prompts is cited by ChinaTalk as a key source of additional revenue. \r\n"}}" id="text-e6a26b47c8" class="cmp-text rte-content js-toc-title"> Why use the gray market? There are several reasons why users seek out gray market or illegal services offering AI model access: cost, access, and some degree of anonymity. Cost: Providers offer discounts between 70-90% off subscription prices. Offerings may be for subscription-based accounts, a certain number of tokens, or a certain number of requests (prompts). With those packages, the allotted number of requests can use an unlimited number of tokens. Access: Users in China often cannot get direct access to U.S. frontier AI models. Frontier U.S. models are either banned or blocked by China, which has a number of AI regulations, or not offered by providers due to national security and distillation concerns. In September 2025, Anthropic took aim at the burgeoning gray market by restricting subsidiaries offering services to unsupported regions like China. Nonetheless, the market is thriving and fraudulent registration is one of the reasons. The Chinese-language offerings, which are on messaging platforms, underground forums and indexed in GitHub repos like this detailed one, appear to outnumber and scale much larger than the smaller-time, English-language cybercriminal offerings. The ChinaTalk blog investigated these Chinese-language gray-market API services, which are referred to as “transfer” or “relay” stations and are advertised on messaging services such as Taobao and Telegram. Vendors have developed sophisticated operations using AI gateways and online uptime monitoring services. Legitimate AI model service providers are trying to counter fraudulent registration. In April 2026, Anthropic said it will use Persona’s ID verification system to verify some new accounts, which involves providing a government-issued ID and a live selfie. To track the proliferation of proxy services catering the Chinese market, Anthropic developed a fingerprinting system to detect account abuse in Asian time zones, although it will be removed as it said it had developed detection methods. Performance: Sophisticated offerings may use AI API gateways such as LiteLLM or OpenRouter to link to a variety of models from different providers, which helps minimize disruptions if accounts are shut down due to abuse. Operational security: If the AI model proxy service is not forwarding the true origin IP, it acts as a way for illicit customers to hide their identity. If the illicit provider is proxying with sophistication, the customer may be able to evade detection. Payment privacy: These services accept cryptocurrency, which may offer a higher degree of privacy than other payment options. Many providers do not require personal information to create accounts. Customer service: Illicit AI vendors may provide customer support if an account is shut down or service is disrupted. However, there are disadvantages: Operational security: While the gray market offers some operational security over direct purchases, it cuts both ways. When services are configured as a gateway proxy, the service provider has full visibility into prompts, as those prompts must be forwarded to a model. This is a privacy concern, as the service provider could accidentally leak or sell data. Disruption: Model providers may unexpectedly cut off accounts as controls to prevent fraudulent accounts are tightened, disrupting complex workflows. Bait and switch: Service providers may advertise access to a frontier-model but deliver a less expensive and less capable model, which may not be evident at purchase. Prompts for cash: Gray market service providers have an incentive to act as an adversary in the middle. Even if it were possible to forward input and output with zero knowledge, a gray market service provider would lose the ability to gather telemetry on their users and the ability to distill frontier models. This source of prompts is cited by ChinaTalk as a key source of additional revenue. Cheaper tokens \r\n Okta Threat Intelligence found more than a half-dozen services advertisements via underground forums and messaging platforms, which represents a fraction of these services. One such site is Poison Claude: \r\n"}}" id="text-6a2d2b8dd1" class="cmp-text rte-content js-toc-title"> Cheaper tokens Okta Threat Intelligence found more than a half-dozen services advertisements via underground forums and messaging platforms, which represents a fraction of these services. One such site is Poison Claude: One site, poison-claude.bitsender.top, offers “unlimited” tokens in plans metered by the number of prompts. It also offers a la carte token packages. Fill out the form to access this content. Advertisements for Poison Claude explain how the service can offer the cheap tokens: by taking advantage of free bonus credits, such as the US$100 bonus credit on AWS for Bedrock accounts. The service plainly states on its website that: “We add those accounts to our pool, your request is routed to a specific account under the hood (you don’t see this) and you get charged 5-15% of the official per-token price depending on the model.” \r\n The flat-fee monthly plans available on Poison Claude are possible due to “the gap between what the upstream providers charge us under bonus credit and what we charge you.” The models offered are Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. \r\n"}}" id="text-aae7603864" class="cmp-text rte-content"> Advertisements for Poison Claude explain how the service can offer the cheap tokens: by taking advantage of free bonus credits, such as the US$100 bonus credit on AWS for Bedrock accounts. The service plainly states on its website that: “We add those accounts to our pool, your request is routed to a specific account under the hood (you don’t see this) and you get charged 5-15% of the official per-token price depending on the model.” The flat-fee monthly plans available on Poison Claude are possible due to “the gap between what the upstream providers charge us under bonus credit and what we charge you.” The models offered are Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. Poison Claude claims it can offer significantly cheaper access to Anthropic’s models due to “bonus credits” that come from buying accounts. Fill out the form to access th [truncated for AI cost control]