Hackers are exploiting a vulnerability to steal Claude tokens from Anthropic subscribers, leading to unauthorized usage and unexpected charges. The issue appears to stem from compromised session data, potentially acquired through infostealer malware, which allows attackers to mint unauthorized Claude Code OAuth tokens. Anthropic has acknowledged the problem, suspending affected accounts, invalidating sessions, and issuing refunds, while also warning users about potential malware on their systems. The company states the vulnerability is not inherent to Claude itself but rather a result of users acquiring malware from external online sources. AI
IMPACT Highlights a critical security risk for AI service users, potentially impacting trust and adoption due to malware-driven token theft.
RANK_REASON The cluster describes a security vulnerability affecting users of an AI product, leading to unauthorized usage and financial loss, but does not originate from the AI provider itself.
Read on Mastodon — mastodon.social →
AI-generated summary · Google Gemini · from 2 sources. How we write summaries →