Skip to content

Leadership1 publisher3 min readPublished

Criminal AI is a $12.99 reseller business now, and the guardrail failing is your vendor's

ThreatDown says the crime storefront Kriminal.ai is just Grok with the safety layer stripped off. That moves the control you depend on from your stack to someone else's.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • A report from endpoint security provider ThreatDown found that a criminal storefront known as Kriminal.ai has been selling guardrail-free AI for hackers at $12.99 a month, marketing itself as "the AI that answers everything".
  • Researchers found Kriminal is not offering access to its own AI models or infrastructure; it offers a storefront, crypto checkout and jailbreak prompt layered on top of AI it rents from frontier AI vendors.
  • ThreatDown claims Kriminal is one of the most popular tools on the criminal AI market.
  • Guiliani said: "By pulling Kriminal's production JavaScript and separately having the tool drop its persona to name its underlying engine, both methods pointed to the exact same reality: behind all the tough talk and custom personas, it's just xAI's Grok with its safety guardrails completely stripped off."
  • Grok is said to be handling the primary offensive work while Claude handles deep analysis and long-context tasks.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

Endpoint security vendor ThreatDown says it took apart a criminal AI storefront called Kriminal.ai and found no criminal AI underneath it: a website, a crypto checkout, a jailbreak prompt, and rented capacity from legitimate frontier vendors, sold at $12.99 a month [1][2]. The consequence for operators is unglamorous but structural, because the control that is failing sits inside a supplier's product, and no vendor currently claims to have fixed it [10].

Kriminal markets itself as a purpose-built model made from scratch for cybercriminals [19]. Marco Guiliani, vice president and head of research at ThreatDown, told Forbes his team pulled the service's production JavaScript and separately got the tool to drop its persona and name its own engine, and that both routes pointed at xAI's Grok with the safety guardrails stripped [4][17]. ThreatDown describes Kriminal as one of the most popular tools on the criminal AI market [3]. Per the report, Grok handles the primary offensive work while Claude is used for deep analysis and long-context tasks [5]. The top tier, Ghost, sells four named agent personas covering financial intelligence, offensive security, code writing, document analysis, social engineering and persona construction [6]. It is on the clear net, indexed by Google, and open to anyone [7].

The pricing is the part to take to a budget meeting. WormGPT, built on GPT-J, sold on HackForums for $110 a month in 2023; FraudGPT was advertised at $200 [8][9]. Kriminal is roughly 12 percent of the WormGPT price and about 6 percent of FraudGPT's [15], or $155.88 a year for the entry tier [16]. The reason the price collapsed is that the seller stopped paying to train and host anything. Reselling somebody else's inference is cheap, and the capability is better than a purpose-built dark model because the underlying model is better [2].

That is the procurement point. Frontier models are vulnerable by construction, because the interface is natural language and jailbreaks and prompt injection are conversations rather than exploits [18]. Anthropic has stated plainly that it suspects perfect jailbreak resistance is not currently possible for any model provider [10]. In June the U.S. government issued an export control directive suspending access to Fable 5 by foreign nationals over jailbreak concerns, which is a regulator treating guardrail failure as a containment problem rather than a patchable bug [11]. Anthropic's April announcement of Mythos flagged the model's ability to discover and exploit vulnerabilities in critical software as a specific concern [14].

So the questions in your next model-vendor review are about downstream abuse, not your own prompt hygiene: what the vendor detects at the API layer, how fast it terminates reseller accounts, and what it will tell you when it does. Your inbound threat model needs the same edit. Ryan Whelan, global head of Accenture Cyber Intelligence, told Forbes the barrier has dropped far enough that a backyard hacker can credibly go after a major organisation, using exposed business data such as real invoices and payment details to build convincing phishing and fraud campaigns [13]. Nothing in your controls changed. The quality of what arrives at them did.

Watch whether xAI publicly cuts Kriminal off, and how long that takes given the storefront is indexed by Google [7]. Watch, too, for the migration Whelan describes, in which criminals move to open-weight models with fewer controls and more anonymity as hosted guardrails tighten [12]. That shift removes vendor-side takedown as an option entirely, and pushes the whole burden back to detection at your perimeter.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories