← Back to articles
Governance5 MIN READ

Discounted Claude Scams Are Stealing Your Business Prompts

Poison Claude sells Claude API access at 5–15% of retail while its operator reads every prompt you send. Here's how SMBs spot these traps before it's too late.

Cameron Breen
Cameron Breen
2026-08-06 · 5 min read
TL;DR

Discounted AI access services like 'Poison Claude' are not bargains; they are data interception operations. The operator of such a service can read every prompt you send, which means every internal process, customer detail, and business logic you type. Researchers at The Hacker News identified more than six illegal AI access ads using this model. If you are buying Claude or GPT access through any channel other than Anthropic or OpenAI directly, you need to verify exactly who sits between you and the model.

What is Poison Claude and why should SMB operators care?

Poison Claude is an unauthorized reseller that offers access to Anthropic's Claude models at roughly 5–15% of standard API pricing. That discount is not a business model. It is the bait. The operator of the service routes your requests through infrastructure they control, which means they can log, read, and store every prompt you send before it ever reaches the actual model. Researchers reported by The Hacker News found more than six similar illegal AI access advertisements circulating in the same period, suggesting this is a pattern, not an isolated incident.

For a small business, the risk is not abstract. Your prompts contain your business. Draft contracts, customer complaints, internal SOPs, financial summaries, sales scripts: these are the things operators actually feed into AI tools every day. Hand that stream to a stranger running a discount API shop and you have handed them a live intelligence feed on your operation.

How does the interception actually work?

When you use a legitimate API from Anthropic or OpenAI, your request travels encrypted from your system to their servers. The model processes it and returns a response. Nobody in the middle reads it.

With a proxy service like Poison Claude, the architecture changes. Your request goes to the operator's server first. Their server forwards it to the real Claude API using credentials they hold. The response comes back through that same server before it reaches you. At every point in that relay, the operator has full access to plaintext content.

This is not a theoretical vulnerability. It is the entire design. The operator has to sit in the middle to charge you less than retail while still paying retail to Anthropic. The price difference has to come from somewhere, and in schemes like this, it comes from selling or exploiting what they learn from your traffic.

The discount is not a feature. It is the product you are actually paying for, from the other side of the transaction.

Why are SMBs specifically targeted by these services?

Cost pressure is real. Claude and GPT-4-class models are not cheap at volume, and a 5–15% pricing offer sounds like a smart procurement move when you are watching margins. Discount AI resellers advertise in the exact places small business operators look: Reddit threads, Facebook groups, Slack communities, and newsletters oriented toward bootstrapped founders.

The Anthropic API pricing for Claude Opus 4 starts at $15 per million input tokens as of mid-2025. A service offering the same access at $0.75–$2.25 per million tokens is not absorbing that difference charitably. Someone is making money on your data, your credentials, or both.

Larger enterprises typically have procurement and security teams that flag unauthorized API intermediaries. SMBs often do not. That gap is the targeting logic.

How do you tell a legitimate tool from a prompt-harvesting relay?

Here are the signals that should stop you before you sign up:

| Signal | Legitimate provider | Red flag | |---|---|---| | Pricing | At or near Anthropic/OpenAI published rates | More than 20–30% below retail | | Authentication | You authenticate directly with the model provider | You log in only to the reseller | | Terms of service | Published, legally accountable entity | Vague, anonymous, or missing entirely | | Data handling | Explicit no-training, no-logging clauses | No mention of what happens to prompts | | API keys | Your own keys from your own account | Keys provided by the service | | Company identity | Verifiable legal entity, registered address | Anonymous operator, Discord-only support |

The API key point deserves emphasis. If you are using a service where you never created an account directly with Anthropic or OpenAI, you do not control the credentials. You are a guest on someone else's access, and they can see everything you do.

What information are you actually exposing?

Think through what a typical SMB puts into an AI tool on any given week:

  • Customer data: names, emails, complaint details, purchase history fed into summaries or responses
  • Financial context: revenue figures, margin discussions, budget planning prompts
  • Legal and HR content: draft agreements, employee performance notes, policy drafts
  • Competitive strategy: market analysis, pricing logic, positioning work
  • Operational SOPs: internal process documentation used as context for automation

All of this is prompt content. All of it is visible to a relay operator. A single month of intercepted prompts from an active SMB user is a detailed intelligence file on that business.

Does using a third-party AI wrapper tool carry the same risk?

Not automatically, but it requires the same scrutiny. Legitimate SaaS tools built on top of OpenAI or Anthropic APIs (think writing assistants, CRM integrations, customer support platforms) have their own data handling policies. Many are transparent and contractually binding. The risk profile is different from an outright interception scheme.

The key questions to ask any AI-powered SaaS vendor:

  1. Do you log my prompts and for how long?
  2. Are my inputs used to train any model, yours or the underlying provider's?
  3. Who has internal access to stored prompt data?
  4. What is your breach notification policy?

A vendor that cannot answer these directly is not ready for business use, even if they are not running an outright scam.

What we'd actually do

  • Centralize API procurement through official channels only. Every team member using Claude or GPT should be operating through accounts and API keys issued directly by Anthropic or OpenAI, or through enterprise agreements with auditable SaaS vendors. No exceptions for cost savings.
  • Run a quick audit of every AI tool currently in use across your team. Ask each person where they got access. If anyone is using a discounted third-party relay, shut it down immediately and rotate any credentials that may have been exposed alongside it.
  • Build a one-page AI tool vetting checklist for your team. It does not need to be complex. Pricing within range of retail, verified legal entity, explicit data handling terms, and direct authentication are the four gates. If a tool fails any of them, it does not get used. If you want a starting framework for this, the AI for Business community at skool.com/aiforbusiness is where we work through exactly this kind of governance with operators building real AI workflows.

FAQ

Is it safe to use discounted Claude or ChatGPT access from a third-party reseller?

No. Services offering Claude or GPT access well below official pricing typically operate as relay proxies, meaning the operator can read every prompt you send. Poison Claude, identified in research published by The Hacker News, is one documented example. Always authenticate directly with Anthropic or OpenAI and use API keys tied to your own account.

How do I know if an AI tool I'm already using is logging my prompts?

Check the vendor's privacy policy and terms of service for explicit language on prompt logging, data retention, and training use. If those documents are absent, vague, or hard to find, treat the tool as unsafe for business-sensitive content. Legitimate providers like Anthropic publish clear data handling policies and offer enterprise agreements with contractual guarantees.

What should I do if I've already used a service like Poison Claude?

Stop using it immediately. Assume any prompts sent through that service are compromised. If you used shared credentials or API keys provided by the service, rotate them now. Review what business information appeared in those prompts, notify relevant parties if customer data was involved, and document the incident in case it becomes relevant to any compliance obligation.

JOIN THE COMMUNITY

Want this running in your business?

The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.

  • Weekly Q&A with Alex and Cameron
  • Templates and frameworks you can steal
  • Real builds, running in real businesses
Join skool.com/aiforbusiness