Grey proxy services are offering access to flagship LLMs for just 5% to 15% of official list prices. Recent reports from Unit 42 and Okta Threat Intelligence reveal what really hides behind this generous discount: classic criminal arbitrage powered by stolen developer credentials (token jacking) and industrial-scale free-trial farming. Services like Poison Claude shamelessly route customer prompts through pools of hijacked corporate accounts while accepting payment strictly in cryptocurrency.
The mechanics of account compromise run like a well-oiled assembly line. Attackers harvest API keys via info-stealers, phishing campaigns, and malicious npm packages such as Shai-Hulud and Miasma. Once in control of an account, hackers immediately max out spend limits, disable automated alerts, and kill audit logging. Victim companies only discover the breach post-factum: Unit 42 documented instances where bills for unauthorized parasite traffic skyrocketed close to $1 million.
Attempting to slash your IT budget through grey gateways directly jeopardizes corporate trade secrets. These shadow proxies are riddled with their own security flaws: Okta researchers found that Poison Claude's administrative endpoint openly exposed active user statistics directly from servers in Mumbai. Furthermore, a study by the CISPA Helmholtz Center calculated that nearly 46% of such gateways quietly swap original models for cheap open-source surrogates. Routing confidential corporate prompts through anonymous intermediaries to save pennies on inference is not cost optimization—it is a voluntary surrender of proprietary data to cybercriminals.