The most expensive intelligence on the internet now has a black market, and it is running a clearance sale. Underground marketplaces are selling unauthorized access to frontier models from Anthropic, Google and OpenAI at discounts of up to 97%, according to findings from Google Threat Intelligence Group (GTIG) reported by the Financial Times on Friday. The same data shows the price of the raw material is going the other way: average underground prices for stolen Claude, Gemini and Cursor Pro accounts have more than doubled in 2026, pushed up by demand for cheaper access to agentic coding capability.
That combination, cheap retail access built on increasingly valuable stolen or fraudulently created accounts, describes a gray market that is maturing into a real business. GTIG says buyer demand on the underground forums it tracks has risen year over year. Most of it is aimed at Claude and Gemini credentials, with growing interest in autonomous coding tools such as Cursor Pro and Devin. Neither GTIG nor the outside researchers who have mapped the trade have published a per-account price sheet, so "more than doubled" shows which way prices are moving. It does not tell us what a stolen login costs.
From Experimentation to Industry
The FT report builds on a thread GTIG has been pulling all year. In its May AI Threat Tracker, the group described an "emerging ecosystem of custom middleware, proxy relays, and automated registration pipelines designed to bypass safety guardrails and billing constraints." Actors using account-pooling services, it wrote, were "effectively industrializing their adversarial workflows while subsidizing their operations through trial abuse and programmatic account cycling." GTIG also warned that API aggregators, when misused, "could enable the reselling of unauthorized API access and mask individual traffic patterns from safety monitoring." Its report named state-linked clusters as well as ordinary cybercriminals among the users.
Independent research in August showed what one of these storefronts looks like. Okta's threat intelligence team documented a service branded Poison Claude that advertised Anthropic's Opus and Sonnet models at 5% to 15% of official per-token pricing and took payment only in cryptocurrency. The margin, Okta found, comes from free credit. The operators pool accounts seeded with promotional cloud credits, including welcome credits of around $100 on Amazon Bedrock, and resell the capacity behind a single proxy. An exposed status endpoint showed 881 users, 872 of them active. A second service, Ecomagent, appeared to draw on Google Cloud's Vertex AI and startup credit programs. Anthropic's own startup credits run from $25,000 to $100,000, which makes that kind of subsidy a tempting target.
Anthropic says the problem goes well beyond a few resellers. "There's an entire illicit ecosystem to try to gain access to Claude and other models," Jacob Klein, the company's head of threat intelligence, told CNBC earlier this month. He added that the ecosystem "goes through any means necessary to evade our controls, so they can spin up accounts at extreme scale." CNBC's reporting linked some of that demand to distillation, where outputs from a frontier model are used to train cheaper rivals, and to users in sanctioned jurisdictions where the major labs restrict access.
Why It Matters
For the model makers, this is revenue leakage that shows up in two places. First, every token served through a farmed trial account or a stolen seat is inference compute the provider pays for and never bills. At 5-15% of list price, a reseller can undercut the official API by an order of magnitude while its own cost of goods is close to zero, because that cost sits on someone else's promotional budget. Second, the leakage distorts the growth programs themselves. Free credits and startup grants are how Anthropic, Google, OpenAI and the cloud platforms compete for developers. If a meaningful share of that spend goes to fraud rings, the labs will tighten sign-up verification and credit eligibility. Legitimate founders will then feel the friction first.
The rising price of stolen accounts is the more telling signal. Commodity credentials usually get cheaper as supply floods in. When prices double, it means buyers value what the account can do, such as long-running agentic coding sessions, more than they fear losing it to a ban. That demand is the same demand behind the labs' premium tiers, and it suggests a real group of price-sensitive developers who are going unserved at current list prices.
For enterprises, the risk is exposure more than cost. Okta's researchers noted that a proxy like Poison Claude can "see every prompt and response," including code, contracts and personal data, and could alter answers without the customer knowing. A developer who routes a coding agent through a discount relay to save money may be sending a company's source code to an anonymous operator. GTIG's tracker also flagged infostealer operators adding rules this year to grab configuration files where AI coding tools store API keys in plaintext. A company's own developer keys can end up as supply for the same market.
What to Watch
Expect the labs and cloud providers to respond in the places where the fraud makes its money: stricter identity checks on free tiers, tighter terms on promotional and startup credits, and more aggressive detection of pooled traffic. That is the mitigation GTIG itself recommends, using signals tied to known API aggregator infrastructure. Watch too for enterprise security teams to start treating unsanctioned AI proxies the way they treat shadow IT, with audits to confirm that model traffic runs through vendor APIs and not through brokered pools. The bigger question is commercial. If the underground keeps proving there are buyers for frontier capability at a fraction of list price, pressure will grow on Anthropic, Google and OpenAI to offer cheaper legitimate tiers before the gray market takes those customers.
“There's an entire illicit ecosystem to try to gain access to Claude and other models.”— Jacob Klein, Head of Threat Intelligence, Anthropic