Hackers exploit infostealers to drain Claude subscription tokens
Hackers are using information-stealing malware to hijack Claude login sessions, allowing them to access accounts and consume subscription tokens without needing passwords. Following reports of unauthorized token usage on platforms like Reddit and GitHub, Anthropic confirmed it is aware of the issue. The company is forcing logouts, revoking authorizations, and issuing refunds to affected users, though it has not yet provided detailed usage logs for individual account audits.
Summaries are written by AI from the original article. Not investment advice.