BREAKING NEWS

Hackers Stealing Claude Tokens via Session Hijacking

According to TechCrunch, AI developer Anthropic has warned subscribers that hackers are stealing Claude login sessions to siphon off their token allowances.

QuickTool Team
QuickTool Team
Sep 8, 20263 min readSource: TechCrunchAI-assisted summary · Automatically reviewed by the QuickTool Quality Pipeline
Share:
Hackers Stealing Claude Tokens via Session Hijacking

In Short

  • TechCrunch reported that hackers are utilizing infostealer malware to capture active login sessions from user computers.
  • Affected subscribers experienced sudden, unexplained spikes in token consumption while their platforms were completely inactive.
  • In response to the security incidents, Anthropic signed users out, invalidated existing authorizations, issued some refunds, and issued warnings.

What Happened?

As reported by TechCrunch, independent AI consultant Grant De Swardt noticed his Claude Max 20x account consuming tokens while inactive. Anthropic later suspended the paid account, invalidated sessions, and issued a partial refund. Investigation results revealed a compromised session key minted unauthorized OAuth tokens. Anthropic subsequently warned other users that bad actors are utilizing infostealer malware—software that steals saved passwords, login credentials, and session data from local computers—to access accounts and deplete usage limits without authorization.

Key Highlights

1

TechCrunch reported that hackers are utilizing infostealer malware to capture active login sessions from user computers.

2

Affected subscribers experienced sudden, unexplained spikes in token consumption while their platforms were completely inactive.

3

In response to the security incidents, Anthropic signed users out, invalidated existing authorizations, issued some refunds, and issued warnings.

Why It Matters

This security issue highlights vulnerability vectors in modern subscription-based artificial intelligence services, where compromised login credentials can lead to unauthorized resource consumption. For sole proprietors and businesses relying heavily on automated workflows and AI agents, such interruptions can disrupt daily business operations and administrative tasks.

💡 Related AI Tools

The incident demonstrates the growing need for robust endpoint security and multi-factor authentication when handling cloud-based artificial intelligence credentials. Professionals managing multiple subscriptions may explore alternatives like Cursor, which allows integration with various open-source models, or implement stricter monitoring for unauthorized API and token activity.

Conclusion

As malicious actors increasingly target artificial intelligence accounts, platform providers face growing pressure to implement transparent usage tracking and detailed itemized logs, enabling subscribers to quickly detect and mitigate unauthorized access before their allowances are fully depleted.
Found this news helpful? Share it with your network!

Tools for the next step

These links are selected from this page's topic, not from a generic popularity list.