Fast Facts
Discounted AI API access priced at 5-15% of list is not a bargain. It is a subsidy funded by farmed or stolen credits, and the invoice arrives as your prompts. Google Threat Intelligence Group says underground prices for stolen Claude, Gemini and Cursor Pro accounts more than doubled in 2026, so demand is outrunning supply.
The fix is procurement discipline, not a ban. Pay only vendors you can trace on an invoice, replace static keys with short-lived tokens, and treat any cheap endpoint an engineer configures as an unapproved data processor.
Discounted AI API access is the newest shadow IT, and it is sold openly. On September 26-27, the Financial Times reported Google Threat Intelligence Group findings that underground marketplaces sell access to Anthropic, Google and OpenAI models at up to 97% off, while average stolen-account prices more than doubled during 2026. The durable lesson is the price gap itself, a diagnostic any procurement team can use.
Why Discounted AI API Access Costs More Than List Price
Okta (NASDAQ:OKTA) Threat Intelligence documented the mechanics on August 4, 2026. A reseller branded Poison Claude sells Anthropic’s Opus 4.6 to 4.8 and Sonnet 4.6 at 5-15% of official per-token pricing. Its own site says requests route to a pooled account behind the scenes, and the margin comes from bonus credits such as the $100 Amazon (NASDAQ:AMZN) gives new AWS Bedrock accounts, which Okta says were probably opened through fraudulent registration. A second service, Ecomagent.in, appeared to run on Google (NASDAQ:GOOGL) Vertex startup credits. Neither vendor beats list price through efficiency. They convert free trials into inventory.
The Proxy Reads Everything
Every reseller in Okta’s write-up sits between your tool and the model, so it must see each prompt in plaintext to forward it. That means source code, contracts and customer records. Buyers connect by setting environment variables that point a coding assistant at the reseller’s endpoint instead of the vendor’s. It notes that ChinaTalk cites harvested prompts as a revenue source, so your traffic may be the product. One reseller’s operators left an unauthenticated status route open that showed 881 registered users.
Verified numbers
| Stat | Detail |
|---|---|
| 5–15% | Reseller price versus official per-token price for discounted AI API access (Okta, Aug 4, 2026) |
| 2×+ | Rise in average underground price of stolen Claude, Gemini, Cursor Pro accounts in 2026 (GTIG via FT) |
| 881 | Registered users on one discounted AI API access reseller, exposed by its own status route (Okta) |
“An entire illicit ecosystem” now exists to reach frontier models, says Jacob Klein, Anthropic’s head of threat intelligence, speaking to CNBC.
Why Lagos and Manila Feel This First
Tokens are priced in dollars, while many developers in Nigeria and Southeast Asia earn in weaker currencies, so a 90% discount reads as a budget line rather than a red flag. Okta names cost and access restrictions as the two demand drivers. Providers are adding ID checks, which in my read pushes price-sensitive buyers toward resellers unless legitimate tiers close the gap. See our analysis where we explain how AI-enabled cybercrime is scaling across Africa.
⚠️ Hypothetical scenario (illustrative only, not a reported case)
A Lagos fintech’s engineering lead sees API spend far below forecast. She traces it to a contractor who pointed the team’s coding assistant at a cut-price “unlimited” endpoint found on Telegram. The repository it touched holds payment-reconciliation logic. The bill was small. The exposure is that a stranger’s server read the code, and nobody can prove responses were unaltered before merging. Her team now audits every base-URL override and rotates every key.
A Procurement Test for Cheap Tokens
Start with the invoice. If a price sits below what cloud credits could subsidize, ask who pays the difference, because discounted AI API access always has a payer. Then remove the currency the gray market trades in. Okta recommends short-lived OAuth 2.0 client-credential tokens over indefinite static keys, since a leaked token expires and a leaked key does not. AI Weekly’s summary of GTIG’s tracker adds that infostealer operators pushed rules in May 2026 to grab plaintext key files used by the Cline and Continue coding extensions, so scanning developer machines for keys is now baseline hygiene. See our analysis where we explain the 140-to-1 identity gap in agentic AI governance.
Cost pressure is legitimate, so give teams a sanctioned way to cut it. See our analysis where we explain how token caching cuts enterprise AI costs, which lowers spend without moving traffic through a stranger. Pair it with an approved-endpoint allowlist and the checks in our breakdown of costly AI agent security blind spots. GTIG’s May 2026 report calls AI a high-value target; stolen access is how that gets monetized. See our analysis where we explain who gets the best AI cybersecurity access tiers.
💡 CreedTec Analyst’s Note by Daniel Ikechukwu
Strategic Impact
Cheap tokens are a supply-chain problem, not a pricing story. Discounted AI API access routes through an unaudited subprocessor with full read access, and the discount is the lure that hides that.
Stop / Start / Watch
- Stop: letting individual engineers or contractors choose their own model endpoints or paste keys into plaintext config files.
- Start: issuing short-lived scoped tokens, allowlisting approved base URLs, and reconciling AI spend against vendor invoices monthly.
- Watch: whether providers extend ID checks and passkey-gated signups to close the free-credit farming that feeds resellers.
ROI Outlook
Reseller savings are small; the downside is a code or customer-data exposure priced in fines and lost contracts. Sanctioned caching and committed-use discounts capture most of the benefit with none of the leakage.
— Daniel Ikechukwu
Is your team buying AI tokens you can’t trace?
Get CreedTec’s weekly briefing on AI vendor risk, procurement checks and cost controls, written for buyers who sign the invoices. Subscribe free.
Sources
- Okta Threat Intelligence: “Free tokens for sale: How fake signups drive AI fraud” (Aug 4, 2026)
- AI Weekly: “Google: Underground AI Account Prices More Than Doubled in 2026” (Sept 27, 2026)
- Financial Times: report on Google Threat Intelligence Group findings (Sept 2026)
- CNBC: Anthropic distillation battle turns to dark web (Sept 3, 2026)
- Google Cloud Blog, GTIG: “Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access” (May 2026)


