Home/ Breaking News/ 8 September 2026
AI Digest
8 Sources Updated 18h ago H0 Edition 1 min read

Claude Tokens Stolen: Anthropic's Paying Users Robbed

The attack came to light when a Claude subscriber noticed his account draining tokens at speed despite sitting idle.

AI-generated digest · 8 verified sources · Updated twice daily Add as preferred source
What You Missed Today
Nutshell
Nutshell
Nutshell automates your follow-ups so no lead falls through the cracks.
Learn more →
Wise
Wise
16 million people moved away from bank FX fees. Wise is where they went.
Learn more →
Brevo
Brevo
The Mailchimp alternative that doesn't charge per contact. Brevo.
Learn more →
Proton
Proton
Your email is read by Google. Proton Mail is end-to-end encrypted. Switch.
Learn more →
Payoneer Workforce
Payoneer Workforce
EOR at $399/month. Payoneer Workforce is $200 cheaper than the competition.
Learn more →

Claude Tokens Stolen: Anthropic's Paying Users Robbed

Anthropic has confirmed that hackers have been systematically stealing API tokens from paying Claude subscribers, according to TechCrunch, in a breach that raises pointed questions about the security infrastructure underpinning the AI industry's fastest-growing products.

The attack came to light when a Claude subscriber noticed his account draining tokens at speed despite sitting idle. Anthropic has since issued warnings to its user base, but the company has not disclosed how many accounts were compromised, how long the operation ran, or what the stolen tokens were subsequently used for — gaps that matter considerably given that Claude tokens represent direct access to one of the most capable AI systems currently available.

The timing is uncomfortable. Anthropic is competing at the highest level of an industry where trust in infrastructure is as commercially critical as model performance. A token-theft operation — however contained — signals that the attack surface around frontier AI platforms is being probed with increasing sophistication. Stolen tokens could be resold, used to run large-scale queries at another user's expense, or leveraged to extract outputs that the legitimate account holder would never have authorised.

Anthropic has not confirmed whether the vulnerability has been fully closed. For enterprise clients building pipelines on Claude, that silence is the detail that will matter most when security reviews come around. Per TechCrunch, the company is continuing its investigation.

*By Isla Camilleri, Global Affairs & Lifestyle Editor — News Beast by FreeMalta.com*

Editor's Note
If Anthropic can't secure the infrastructure of a product whose entire pitch is "trust us with your most sensitive work," that's not a security story — that's a brand story.
Isla Camilleri
Isla Camilleri
Global Affairs & Lifestyle Editor
Isla Camilleri lost her mother at four, grew up in every city her diplomat father was posted to, married at 22 and left at 23, and came back to Malta to open a café-boutique in Valletta that sells couture and coffee to people who understand both. She covers the world the way someone searches for something — thoroughly, and without quite finding it.
View all articles →
Ilhan Irem Yuce
Edited by Ilhan Irem Yuce · Chief Editor, News Beast