A Market That Got More Expensive, Not Cheaper

Google's threat intelligence team reports that underground prices for stolen AI accounts more than doubled in 2026, even as the company and its rivals pushed harder against the trade. The finding comes from a GTIG report published September 8, titled "From Prompting to Autonomy," which tracked posts on underground forums and found buyer demand concentrated on Claude and Gemini credentials, with rising interest in autonomous coding tools like Cursor Pro and Devin.

A rising price in a black market usually means demand is outrunning supply, not that enforcement is winning. Anthropic, Google and AWS have all fielded abuse reports this year about pooled and resold AI access, yet the going rate for a working account climbed rather than fell. That points to a market that has found a stable customer base willing to pay for capacity it did not have to buy itself.

The Retail Layer: A Reseller Called Poison Claude

Poison Claude is a gray market service that sells access to Anthropic's Opus 4.6, 4.7 and 4.8 models plus Sonnet 4.6 at 5 to 15 percent of the official per-token price, according to an Okta Threat Intelligence report published August 4. It builds its supply by opening accounts that claim Amazon's promotional AWS Bedrock credits, 100 dollars for signing up and another 100 dollars for completing account activity, then pools those accounts behind its own programmatic gateway.

Customers pay a flat monthly fee based on prompt volume, settled in Tether, USD Coin, Ethereum, Litecoin or Bitcoin, and receive an API key that quietly redirects their Claude-compatible tools through Poison Claude's own server instead of Anthropic's. From the customer's side, the model still answers. What changed is who sits in the middle of every request.

Why a Discount Reseller Is a Man in the Middle

Every prompt a Poison Claude customer sends passes through infrastructure that customer does not control, which means its operator can read, log or alter both the request and the response without either side knowing. That risk is not theoretical for the service's own users: Okta found an exposed status endpoint at api.claudeopus.shop, hosted with a provider in Mumbai, that quietly listed 881 total accounts and 872 active ones.

A service built on secretly proxying other people's AI traffic could not keep its own operational numbers private. Okta notified Cloudflare, Anthropic, AWS and Google Cloud. Cloudflare, which fronts the domain, added a phishing warning but had not taken the site down as of mid July.

The Wholesale Layer: Attackers Stealing Access To Run Their Own Tools

A separate class of theft skips resale entirely and feeds an attacker's own operation. GTIG documented ACRSTEALER malware that, in May 2026, targeted the configuration files of AI coding assistants directly, pulling the secrets.json file from Cline and the config.yaml file from Continue AI to harvest plaintext API keys, custom model routing settings and access to a victim's own paid usage quota.

Those stolen credentials then feed automation that no longer needs a human at the keyboard. GTIG traced one campaign in which an attacker used an AI coding chatbot with a set of agent instructions to run vulnerability scanning, troubleshoot failures and rotate IP addresses in real time, compromising thousands of third party credentials in under six hours from start to finish. A related framework the team calls Recon organized more than 23,800 harvested secrets into a live, searchable dashboard for the attacker.

From Reselling To Renting Your Own Cloud Against You

The clearest example of what a stolen AI credential buys an attacker is a single exposed GitHub access token from April 2026. GTIG traced how that one credential let an attacker enable Gemini Enterprise inside the victim's own cloud account, provision new compute, and deploy an open source routing tool alongside an autonomous agent framework on a public facing service.

From there the attacker used the account's own cloud quota system to request NVIDIA RTX 6000 hardware and launched instances with 48 virtual CPUs, all billed to the victim, to run unauthorized AI workloads. The four stages below did not happen in one single campaign, but together they trace where this market is heading.

StageExampleWhen
Retail resale of pooled accountsPoison Claude sells Anthropic model access at 5-15 percent of list priceReported August 2026
Malware targets AI tool configsACRSTEALER pulls API keys from Cline and Continue AI config filesMay 2026
Autonomous mass credential theftAgent-run campaign compromises thousands of credentials with no human stepUnder 6 hours, Q2 2026
Stolen key rents computeOne GitHub token leads to GPU compute requested on the victim's own accountApril 2026

What This Means If You Issue AI Access To Your Team

An AI API key now unlocks the same things a cloud credential does: paid compute, a usage quota and, if it is stolen from a coding assistant's config file, a direct line into whatever that assistant was working on. Treat every Claude, Gemini, Cursor or Devin key with the same rotation, scoping and monitoring discipline already applied to cloud IAM credentials, rather than as a convenience setting typed once and forgotten.

Two habits follow directly from what GTIG and Okta documented. Rotate the credentials stored in coding assistant config files, including secrets.json and config.yaml, on the same schedule as CI secrets, since malware now targets those files by name. And treat any AI access offered well below the vendor's own price as a service that can read what you send it, not a bargain, because that is the only way the arithmetic works.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.