# The AI Middleman Trap: How "Poison Claude" Turned Cheap API Access Into a Surveillance Play


Discount access to Claude. No API key required. Just pay less and get the same model. Sounds like a deal — until you realize the operator running the service is reading every word you type.


That's the scheme researchers uncovered with a service calling itself Poison Claude: a third-party wrapper that markets itself as a budget route to Anthropic's flagship model while silently logging all customer prompts on its own infrastructure. The name, in hindsight, is almost honest.


## What "Reselling" Actually Means Here


To understand why this works, you need to understand how Claude's API access model operates. Anthropic sells API access directly. Developers build products on top of it. That's legitimate. But nothing technically stops an operator from becoming an unauthorized middleman — buying API access, marking it up (or in this case, down), and routing user traffic through their own servers first.


That routing is the attack surface.


When you send a message through a legitimate Claude-powered app, Anthropic's systems receive it. When you send it through Poison Claude, it hits their servers first. They log it, process it, and optionally forward it to Anthropic's API. From the user's perspective, the response looks the same. Under the hood, every confidential query — strategy documents, internal business problems, draft legal filings, personal questions — now lives on someone else's server.


This isn't a zero-day exploit. No CVE required. It's business model as attack vector.


## Who Actually Gets Burned


The customer profile for "discounted AI access" services skews toward specific groups: early-career professionals who can't expense API costs, small teams operating on tight margins, researchers at resource-constrained institutions, and frankly, anyone who Googles "cheap Claude API alternative." These are people likely to paste in real work. Competitive analysis. Code with embedded credentials. HR notes. Acquisition research.


The friction of getting an official API key — creating an Anthropic account, waiting for access, managing billing — creates exactly the demand these services exploit. The discounting is a feature of the scam, not incidental to it.


There's also a secondary exposure that's easy to miss: prompt injection risk. An operator who controls the middleware layer doesn't just see your prompts. They could modify them. Send you a manipulated response. Feed your prompts back into a fine-tuning pipeline to harvest task patterns across a user base. The interception point opens doors beyond simple logging.


## The Wrapper Problem Has Been Here for Years


This isn't the first time third-party AI wrappers have created security exposure — it's just the most brazenly branded instance. When OpenAI's API became widely available in 2022-2023, a wave of unofficial "GPT-4 for $X/month" services appeared across Discord, Telegram, and obscure payment processors. Security researchers flagged the same structural problem then: users couldn't verify what happened to their prompts on the upstream server.


What's changed is scale and sophistication. As Anthropic's Claude models have become competitive enough that users specifically seek them out by name, the impersonation surface grows. "Poison Claude" benefits from brand recognition Anthropic spent significant resources building.


Anthropic's terms of service prohibit unauthorized resale and require operators to be transparent about what they're building. But ToS enforcement is reactive. By the time Anthropic identifies and terminates an operator account, a service running this play has already harvested weeks or months of user data.


## What Defenders Should Actually Do


For security teams, this fits squarely into the category of shadow IT meets AI supply chain risk. Employees using unauthorized AI wrappers represent a data exfiltration vector that most DLP tools aren't tuned to catch — the traffic looks like HTTPS to a plausible-seeming API endpoint.


A few practical responses:


  • Audit outbound AI API traffic. If you don't have visibility into which AI endpoints your employees are hitting, you're flying blind. Legitimate enterprise Claude usage should route through api.anthropic.com. Anything else warrants scrutiny.
  • Establish clear AI usage policy with named approved services. "Don't use unapproved AI tools" is a losing battle. "Use these specific approved tools, accessed this specific way" is enforceable.
  • Educate on the wrapper risk model specifically. Users who'd never paste sensitive data into a random web form will happily paste it into something that looks like an AI product. The mental model of "it's just the AI" needs updating.
  • If you're an individual user: Verify you're accessing models directly through official channels. Check the domain. Look for Anthropic's own apps or verified enterprise integrations. Discounts should raise your suspicion, not your enthusiasm.

  • ---


    ## HackWire Analysis


    The Poison Claude case is worth watching not just as a one-off scheme but as an early signal of what AI supply chain fraud looks like at scale.


    The history of widely-adopted developer tools follows a predictable arc: adoption drives demand, demand drives an ecosystem, and ecosystems attract bad actors who exploit the trust users extend to legitimate products. We saw it with npm packages hiding malicious payloads, with typosquatted PyPI libraries, with fake VS Code extensions. The attack surface shifts to wherever trust is high and verification is low.


    AI model access is now in that zone. Users trust Claude's name. They're less likely to scrutinize the infrastructure delivering that model than they would be to scrutinize, say, a random payment processor. And because the underlying output looks correct — Anthropic's actual model is probably still running on the backend — there's no obvious signal that anything is wrong.


    The more insidious long-term risk isn't just data theft. It's that a sufficiently sophisticated operator could run A/B experiments on modified system prompts, identify high-value targets based on prompt content, or build a dataset of real-world enterprise AI usage patterns worth far more than any individual piece of stolen data. The business model here scales.


    Anthropic needs to make operator legitimacy more legible to end users. A verifiable certificate or published registry of sanctioned API partners — something analogous to Apple's developer verification model — would raise the cost of impersonation significantly. Right now, the verification burden falls entirely on the user, which is exactly where it shouldn't be.


    The name "Poison Claude" will fade. The business model won't.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)