BharatBriefly
Read less. Ask more.

Intelligent News Feed

Loading…

Hackers Stealing Claude Tokens From Subscribers Via Compromised Sessions

· Technology · TechCrunch

Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed his Claude Max 20x token usage rising on August 4, 2024, despite performing no work and having scheduled tasks paused. Anthropic suspended his paid account, invalidated his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 after confirming his token allowance was being depleted. The company later informed him that a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens by an unknown third-party service. De Swardt discovered on Reddit that other subscribers faced similar unexplained usage spikes, including accounts being auto-upgraded without consent and credit cards charged. Because account support tracks total usage rather than itemized usage, this type of token theft could continue undetected for months.

Why it matters

AI software subscribers face security risks and unexpected financial charges when compromised session keys allow unauthorized third parties to siphon token allowances.

Read the original report — TechCrunch

Join us on Telegram
Breaking news the moment it lands. At 10,000 members we ship the Android app.