Hackers are stealing Claude tokens from subscribers

Hackers are exploiting compromised Claude session keys to mint unauthorized OAuth tokens and steal API usage from subscribers. Anthropic confirmed the attack vector and invalidated affected tokens, but noted that itemized usage logs are unavailable, making detection difficult for victims. Multiple users reported similar unauthorized consumption.

Cover image for Hackers are stealing Claude tokens from subscribers