Leadership1 distinct publisher3 min readUpdated
ThreatDown says the crime storefront Kriminal.ai is just Grok with the safety layer stripped off. That moves the control you depend on from your stack to someone else's.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
ThreatDown says the crime storefront Kriminal.ai is just Grok with the safety layer stripped off. That moves the control you depend on from your stack to someone else's.
Endpoint security vendor ThreatDown says it took apart a criminal AI storefront called Kriminal.ai and found no criminal AI underneath it: a website, a crypto checkout, a jailbreak prompt, and rented capacity from legitimate frontier vendors, sold at $12.99 a month [1][2]. The consequence for operators is unglamorous but structural, because the control that is failing sits inside a supplier's product, and no vendor currently claims to have fixed it [10].
Kriminal markets itself as a purpose-built model made from scratch for cybercriminals [19]. Marco Guiliani, vice president and head of research at ThreatDown, told Forbes his team pulled the service's production JavaScript and separately got the tool to drop its persona and name its own engine, and that both routes pointed at xAI's Grok with the safety guardrails stripped [4][17]. ThreatDown describes Kriminal as one of the most popular tools on the criminal AI market [3]. Per the report, Grok handles the primary offensive work while Claude is used for deep analysis and long-context tasks [5]. The top tier, Ghost, sells four named agent personas covering financial intelligence, offensive security, code writing, document analysis, social engineering and persona construction [6]. It is on the clear net, indexed by Google, and open to anyone [7].
The pricing is the part to take to a budget meeting. WormGPT, built on GPT-J, sold on HackForums for $110 a month in 2023; FraudGPT was advertised at $200 [8][9]. Kriminal is roughly 12 percent of the WormGPT price and about 6 percent of FraudGPT's [15], or $155.88 a year for the entry tier [16]. The reason the price collapsed is that the seller stopped paying to train and host anything. Reselling somebody else's inference is cheap, and the capability is better than a purpose-built dark model because the underlying model is better [2].
That is the procurement point. Frontier models are vulnerable by construction, because the interface is natural language and jailbreaks and prompt injection are conversations rather than exploits [18]. Anthropic has stated plainly that it suspects perfect jailbreak resistance is not currently possible for any model provider [10]. In June the U.S. government issued an export control directive suspending access to Fable 5 by foreign nationals over jailbreak concerns, which is a regulator treating guardrail failure as a containment problem rather than a patchable bug [11]. Anthropic's April announcement of Mythos flagged the model's ability to discover and exploit vulnerabilities in critical software as a specific concern [14].
So the questions in your next model-vendor review are about downstream abuse, not your own prompt hygiene: what the vendor detects at the API layer, how fast it terminates reseller accounts, and what it will tell you when it does. Your inbound threat model needs the same edit. Ryan Whelan, global head of Accenture Cyber Intelligence, told Forbes the barrier has dropped far enough that a backyard hacker can credibly go after a major organisation, using exposed business data such as real invoices and payment details to build convincing phishing and fraud campaigns [13]. Nothing in your controls changed. The quality of what arrives at them did.
Watch whether xAI publicly cuts Kriminal off, and how long that takes given the storefront is indexed by Google [7]. Watch, too, for the migration Whelan describes, in which criminals move to open-weight models with fewer controls and more anonymity as hosted guardrails tighten [12]. That shift removes vendor-side takedown as an option entirely, and pushes the whole burden back to detection at your perimeter.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Researchers found Kriminal is not offering access to its own AI models or infrastructure; it offers a storefront, crypto checkout and jailbreak prompt layered on top of AI it rents from frontier AI vendors.
Anthropic stated: "We suspect that perfect jailbreak resistance is not currently possible for any model provider."
Frontier AI models such as Grok and Claude are inherently vulnerable to compromise due to their use of natural language, making it easy for threat actors to use jailbreaks and prompt injection to sidestep content moderation controls and produce malicious outputs.
According to Guiliani, Kriminal markets itself as a custom-built frontier model made from scratch just for cybercriminals.
A report from endpoint security provider ThreatDown found that a criminal storefront known as Kriminal.ai has been selling guardrail-free AI for hackers at $12.99 a month, marketing itself as "the AI that answers everything".
Guiliani said: "By pulling Kriminal's production JavaScript and separately having the tool drop its persona to name its underlying engine, both methods pointed to the exact same reality: behind all the tough talk and custom personas, it's just xAI's Grok with its safety guardrails completely stripped off."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor report, named method, no replication
The core technical claim is attributed to a named researcher and rests on two disclosed methods (production JavaScript inspection and persona-drop interrogation), which is better than an anonymous assertion. But the cluster contains a single publisher relaying a single vendor's report, with no independent replication, no artifacts or indicators published, and no comment from xAI or Anthropic. Several supporting assertions — the Grok/Claude task split, the June Fable 5 export directive, the popularity ranking — carry no method or documentation at all.
Product is real and reachable; uptake unmeasured
There is concrete evidence that the offering exists, is priced, is tiered, and is reachable by anyone on the clear net and indexed by Google — that is more than a proof of concept. What is missing is any measure of usage: no subscriber counts, revenue, transaction volumes, forum-listing data, or observed intrusions traced to Kriminal output. The 2023 precedents establish a market pattern but say nothing about this product's uptake.
Framing outruns the single-source verification
The substantive finding — a thin reseller wrapping a jailbreak prompt around rented frontier inference at $12.99 a month — is well matched to the reported evidence. The overstatement sits in the surrounding framing: 'one of the most popular tools on the criminal AI market' is unquantified, the Grok/Claude division of labour is asserted passively, and expert quotes escalate to a general 'lower barrier to advanced cybercrime' without incident data. No vendor response or enforcement outcome is reported, so the claimed shift in where the guardrail failure lives is directionally plausible but under-verified.
All named sources sell the remedy
The originating research comes from ThreatDown, an endpoint security vendor whose report is the news peg, and the two supporting expert voices are from Accenture Cyber Intelligence and KPMG risk services — all commercially positioned to benefit from heightened enterprise concern about criminal AI and agent governance. Kriminal itself has an incentive to overstate its own sophistication, which the report notes. No disclosure of these interests appears in the article, and no party with an incentive to contest the findings (xAI, Anthropic) is quoted.
Plausible core finding, thin corroboration
Confidence is moderate: the attribution method is disclosed and internally consistent, the pricing and clear-net availability details are specific and checkable, and the Anthropic jailbreak-resistance quote is a direct citation. Against that, the cluster has one publisher and one primary research source, several unverifiable named artifacts, no adoption measurement, and unmitigated commercial incentives among all quoted parties.
product
The criminal AI market is a reseller business, and Grok's abuse desk is the chokepoint1 distinct publisher
product
A school agenda shipped with "Vitoiis" and a planet named Marc, and no one read it first1 distinct publisher
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
build
Grok Build's real product is the X timeline, not the code generator1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026