Hackers steal Claude tokens from subscribers
anthropic claude
| Source: TechCrunch | Original article
Hackers have accessed Claude accounts, causing unauthorized token usage, prompting Anthropic to issue a warning to subscribers.
Hackers have begun siphoning paid‑usage tokens from Anthropic’s Claude AI platform, a development that threatens both users’ wallets and the confidentiality of their AI‑generated content.
The problem came to light when a Claude subscriber, identified only as De Swardt, noticed that his account was consuming tokens despite no active work. An investigation revealed that a hacker had gained access to his Claude session and was covertly draining the token balance. Because Anthropic’s support tools report only total usage and not a detailed breakdown, the theft could have persisted for months before detection, according to a TechCrunch report.
Anthropic confirmed the issue in a warning to users, noting that the attack chain involves infostealer malware that captures active Claude login sessions. The stolen session token grants the attacker full access to the account’s quota without needing the password, allowing the malicious party to run arbitrary workloads and even reinfect the victim’s device after a cleanup. A Reddit user later reported receiving an Anthropic notice about an attempted token theft via the API, underscoring that the threat is spreading across both web and programmatic interfaces.
The breach matters because Claude’s token model underpins the pricing of its premium tiers; unauthorized consumption directly translates into financial loss for subscribers and could erode trust in the platform’s billing transparency—a concern already raised in recent class‑action litigation over Anthropic’s Max subscription tier. Moreover, session hijacking exposes the content of private AI conversations, raising data‑privacy stakes for enterprises and developers who rely on Claude for confidential tasks.
Anthropic advises users to monitor total token usage, revoke and regenerate session tokens regularly, and employ endpoint protection that can detect infostealer activity. Going forward, observers will watch for further disclosures about the scale of the campaign, any additional attack vectors targeting other AI services, and whether Anthropic will introduce granular usage logs or stronger session authentication to curb future thefts.
Sources
Back to AIPULSEN