Technology
Hackers target Anthropic Claude subscriber tokens through infostealer malware
TechCrunch reports that attackers are draining Claude subscription tokens by exploiting compromised login session credentials.
The short version
- Hackers are obtaining Claude session keys through infostealer malware to access subscriber accounts and consume usage quotas.[TechCrunch]
- Anthropic notified affected users, revoked compromised sessions and server-side OAuth tokens, and issued account refunds.[TechCrunch]
- Affected subscribers identified unexplained usage surges, though some report finding no evidence of device infection.[TechCrunch]
Key facts
- Subscribers experienced unexpected spikes in token usage when not actively using their accounts.[TechCrunch]
- Anthropic stated that bad actors used common infostealer malware to compromise login sessions and consume account limits.[TechCrunch]
- Anthropic suspended affected accounts, invalidated server-side tokens, and provided partial subscription refunds.[TechCrunch]
What remains uncertain
- It remains unclear how certain subscribers were compromised, as at least one affected user reported finding no evidence of local malware.[TechCrunch]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.