AI Weekly Malaysia

Back to items Summaries

Anthropic cracks down on hijacked user accounts mining AI tokens

ID
19977
Status
summarized
Published
01 Sep 2026, 12:03 AM
Fetched
01 Sep 2026, 4:50 AM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/08/31/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/5293461
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
6.5
Created
01 Sep 2026, 4:50 AM
Tags
Audience
developersai_agent_userssaas_founders

What happened

Anthropic is detecting infostealer malware campaigns that steal Claude session cookies and credentials, allowing attackers to freeload on victims' paid Claude usage. In at least one confirmed case, Anthropic proactively logged the user out and deleted their stored payment method after detecting attempted fraud via the API. Anthropic emphasized this is commodity infostealer malware, not a Claude-specific vulnerability.

Why it matters

If you use Claude with a saved payment method and Google SSO, your account is a target for session-cookie theft via standard infostealer malware. Remove saved payment methods when not actively needed, periodically revoke active sessions, and treat your Claude session cookies as financially valuable credentials.

Discussion angle

How should AI API providers balance proactive fraud detection (like deleting payment methods without consent) against user friction, and what session hygiene should builders using paid AI APIs adopt as standard practice?

Top