3 / 2455

Hackers are stealing Claude tokens from subscribers

TL;DR

Last month, a Claude user noticed his account was consuming tokens even though he wasn't working. Anthropic has since warned users about hackers. Last month, a Claude user noticed his account was consuming tokens even though he wasn't working. Anthropic has since warned users about hackers.

Nauti's Take

Anthropic going public about account takeovers gives teams a chance to react early, and that transparency is the upside of the report. The risk is concrete: anyone spreading Claude access across scripts, shared keys, or stale sessions usually spots the theft only in the usage graph.

Teams running Claude in production should audit active sessions, rotate keys, and switch on consumption alerts.

Sources