Tech & AI News
TechCrunch

Hackers are stealing Claude tokens from subscribers

Anthropic found that a compromised Claude session key was used to mint unauthorized OAuth tokens, allowing a hacker to siphon tokens and inflate usage. The company suspended affected accounts, invalidated all sessions, issued partial refunds, and warned that infostealer malware may be stealing login sessions. Similar token-theft reports appeared on Reddit and GitHub, prompting Anthropic to revoke authorizations and advise customers to scan for malware.