Security/ anthropic · claude · account-security · token-theft

Anthropic Warns Claude Users After Token Theft Reports

After a subscriber found his account burning through tokens he never used, Anthropic told users hackers are targeting Claude accounts.

Someone is quietly draining Claude subscribers' token balances, and Anthropic is telling users to watch their accounts.

The pattern surfaced last month, when a Claude subscriber noticed his account had burned through tokens on a day he hadn't touched the service. Anthropic has since warned users that hackers are behind at least some of this unexplained usage. Beyond that acknowledgment, Anthropic hasn't detailed how attackers are getting in, how many accounts are affected, or what they're doing with the stolen capacity. The warning itself, not a full incident report, is what's public right now.

This is the token-economy version of a stolen credit card: instead of siphoning cash, attackers siphon compute that subscribers already paid for. It echoes years of OpenAI API keys getting scraped from public repos and drained by bots, except here the target appears to be consumer subscription accounts rather than developer API keys. That shift matters because subscription accounts typically get less monitoring and no per-key spending alerts, making theft harder to spot until someone notices their usage meter moving on its own.

Anthropic says it's watching. Subscribers, for now, are the ones doing the watching.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →