Recent reports reveal a security issue affecting Claude subscribers, as users discover their allocated tokens are rapidly depleting without their input. Anthropic has confirmed that infostealer malware is being utilized to harvest active session tokens from compromised personal computers, allowing unauthorized third parties to drain subscription allowances.
The issue came to light when independent professionals noticed unexpected spikes in token usage during inactive periods. The lack of detailed usage logs and itemized tracking tools by the platform has left many users unaware of the unauthorized activity until significant portions of their allowances are consumed.
While Anthropic has responded by terminating compromised sessions and issuing partial refunds, some affected individuals are migrating to alternative AI platforms due to ongoing transparency concerns. This situation highlights the growing security challenges surrounding generative AI subscriptions and credential protection.
- Hackers stealing Claude tokens via hijacked user sessions.
- Infostealer malware identified as the vector for credential theft.
- Anthropic revoking compromised sessions and issuing refunds.
- Lack of itemized usage tracking frustrates affected subscribers.
Sources:
