‘Session Keys Stolen’ – Hackers Steal Claude Tokens From Paying Subscribers

Hackers have been ‘draining’ usage tokens from the accounts of Paying Subscribers of Anthropic’s Claude AI large language model by hijacking their login sessions to the platform, reports TechCrunch.

The phenomenon came to light when independent AI consultant, Grant De Swardt, noticed that although he had not been using Claude (on a paid-for ‘Claude Max 20x’ plan) on a particular day, his token usage had increased on that day. He notified Anthropic of the issue the following day and, after the company had suspending his paid-for account and, in the words of De Swardt, ‘invalidated all sessions and server-side Claude Code tokens’, issued a partial refund of £44.49 (half of the remaining portion of the subscription cost of $200 per month for Claude Max 20x).

De Swardt was advised by the company that, after investigating the unusual activity, that a compromised Claude session key had been used to generate ‘unauthorized Claude Code OAuth tokens’. In essence, his Claude account had been used by an ‘unauthorized third-party service’ that happened to have been processing activity for other people as well. De Swardt, who raised the issue on Reddit, was unable to establish how the ‘hacking’ had taken place although the evidence was consistent with either ‘stolen credentials or session data’ or ‘connection to an external service’. In the interim, other users came forward on the same Reddit thread to report similar issues with Claude.

One reported that his account had been ‘auto-upgrade[d] without consent’ and ‘charge[d]’ in the process – with the resulting usage suddenly jumping from 0% to 100%. Another reported that, within 12 minutes of using Claude to enter a few prompts and then conducting a simple web search, his account’s usage had suddenly shot up from 0% to 49%. And a third – who had found that his account had ‘exhausted its maximum daily tokens for three consecutive days with no activity’ – raised the matter via a GitHub issue.Anthropic eventually sent an email to some of the affected users – including the party who had discovered that his account had ‘sprinted’ through its maximum daily allowance of tokens over three consecutive days while he was doing nothing with the service – warning that a ‘bad actor’ was using ‘infostealer malware’ to ‘steal logged in Claude sessions from user computers and then drain tokens from their accounts’.

The company emphasized that the malware in question does not come from Claude itself and can be contracted from a variety of online sources including, by way of example, via ‘downloader[ies] infected with the malware’ and ‘ads infected with the malware’. In those circumstances, Anthropic explained that, in order to protect the affected users, it had signed them out of Claude, ‘Rejected all Authorizations for those sessions’, and issued refunds to those users deemed to have been affected.

Keep reading

Unknown's avatar

Author: HP McLovincraft

Seeker of rabbit holes. Pessimist. Libertine. Contrarian. Your huckleberry. Possibly true tales of sanity-blasting horror also known as abject reality. Prepare yourself. Veteran of a thousand psychic wars. I have seen the fnords. Deplatformed on Tumblr and Twitter.

Leave a comment