The information comes from TechCrunch rather than a primary source.

TechCrunch reports that Anthropic learned of a bad actor who steals Claude login sessions from users’ computers and consumes their usage limits.

In one case described by the publication, a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens, access keys for signing in on a user’s behalf.

When Anthropic saw suspicious activity, it signed users out, invalidated existing authorizations, issued some refunds, and warned them that they may have malware.

Claim check:

  • TechCrunch reports that Anthropic learned of a bad actor who steals Claude login sessions from users’ computers and consumes their usage limits. (confirmed only by the carrying publication: evidence; «We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,»)
  • In one case described by the publication, a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. (confirmed only by the carrying publication: evidence; «A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens.»)
  • When Anthropic saw suspicious activity, it signed users out, invalidated existing authorizations, issued some refunds, and warned them that they may have malware. (confirmed only by the carrying publication: evidence; «When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds, and warned them that they may have malware.»)

Publications:

score 67.5 · kind incident · revision 1 · stories st-13k3mke