A service operating under the name Poison Claude has been selling discounted access to Anthropic's Claude AI while quietly recording every prompt submitted by its customers, according to a report published by The Hacker News. The setup exploits the gap between what users expect from a Claude-powered product and what actually happens to their data once it leaves their keyboard.
The service positions itself as a cheaper way to use Claude, attracting users who want API access without paying full Anthropic pricing. But the operator has built in a mechanism that intercepts and stores every customer prompt before it ever reaches Anthropic's servers. Users receive real Claude responses, so nothing feels wrong. The logging happens invisibly in the background.
How the Scheme Works
Reselling access to large language models has become a cottage industry. Operators obtain API keys, mark up or discount the service, and route customer traffic through their own infrastructure. When done legitimately, this is a standard business model. The problem with Poison Claude is that it adds an undisclosed data collection layer, turning every customer interaction into a surveillance feed for the operator.
Key Facts
- Poison Claude markets itself as offering discounted access to Claude AI
- The operator intercepts and stores every customer prompt without disclosure
- Users receive genuine Claude responses, making the logging invisible
- No privacy policy or data handling terms appear to be provided to customers
- The scheme exploits the operator layer that sits between users and Anthropic's API
This is not the first time bad actors have attempted to exploit access to Claude through indirect channels. Anthropic has previously accused Alibaba of illicitly accessing Claude, pointing to a broader pattern of entities attempting to use the model outside sanctioned terms. In that case, the concern was unauthorized use at scale. Poison Claude raises a different but related issue: authorized API access being weaponized against the very customers the operator is supposed to serve.
Users signing up for discounted AI access rarely consider that the discount might be subsidized by the value of their own data.The Hacker News
The Operator Trust Problem
Anthropic's usage policies require operators to handle user data responsibly and to be transparent about data practices. The company has no direct relationship with end users of third-party Claude deployments, which creates enforcement challenges. Anthropic sets the rules, but it depends on operators to follow them. When an operator decides to break those rules, the users downstream bear the consequences.
The situation puts a spotlight on how much trust users implicitly extend when they access AI through a third-party wrapper. Someone submitting a sensitive business query, a legal question, or personal information through Poison Claude has no indication that the prompt is being harvested. The interface looks like a normal Claude product because it largely is one, just with an extra pair of eyes attached.
Security researchers have pointed out that the economic incentive here is clear. Prompt data from AI users has value. It reveals professional interests, business strategies, creative projects, and personal concerns. An operator who collects enough of it could sell that data, use it for competitive intelligence, or target users in other ways. The discount offered to customers effectively functions as a price reduction in exchange for data they never agreed to hand over.
For users who have been following latest Claude AI news, incidents like this are a reminder that accessing Claude through unofficial or discounted channels carries real risks. Anthropic publishes Claude's model family with clear direct access options, and using those official channels remains the safest way to interact with the model without worrying about intermediary data collection. The Poison Claude case is unlikely to be unique. Where there is a price gap to exploit and a data stream to tap, others will attempt similar schemes.