← Latest briefing

Technology

Hackers target Anthropic Claude subscriber tokens through infostealer malware

TechCrunch reports that attackers are draining Claude subscription tokens by exploiting compromised login session credentials.

The short version

  • Hackers are obtaining Claude session keys through infostealer malware to access subscriber accounts and consume usage quotas.[TechCrunch]
  • Anthropic notified affected users, revoked compromised sessions and server-side OAuth tokens, and issued account refunds.[TechCrunch]
  • Affected subscribers identified unexplained usage surges, though some report finding no evidence of device infection.[TechCrunch]

Key facts

  • Subscribers experienced unexpected spikes in token usage when not actively using their accounts.[TechCrunch]
  • Anthropic stated that bad actors used common infostealer malware to compromise login sessions and consume account limits.[TechCrunch]
  • Anthropic suspended affected accounts, invalidated server-side tokens, and provided partial subscription refunds.[TechCrunch]

What remains uncertain

  • It remains unclear how certain subscribers were compromised, as at least one affected user reported finding no evidence of local malware.[TechCrunch]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.