News MajlisShared story
Steals Claude tokens from accounts via malware

Hackers stealing Claude tokens from subscribers via compromised sessions

Anthropic users report unauthorized token consumption on their Claude accounts. An independent AI consultant in East Sussex noticed his token usage climbing despite no work. Anthropic identified compromised session keys and infostealer malware stealing login credentials. The company issued refunds and warned affected users, but lacks itemized usage tracking that could detect theft earlier.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email to affected users.
Read the full story in News Majlis › View at TechCrunch ›