Claude Tokens Stolen: Anthropic's Paying Users Robbed
The attack came to light when a Claude subscriber noticed his account draining tokens at speed despite sitting idle.
Claude Tokens Stolen: Anthropic's Paying Users Robbed
Anthropic has confirmed that hackers have been systematically stealing API tokens from paying Claude subscribers, according to TechCrunch, in a breach that raises pointed questions about the security infrastructure underpinning the AI industry's fastest-growing products.
The attack came to light when a Claude subscriber noticed his account draining tokens at speed despite sitting idle. Anthropic has since issued warnings to its user base, but the company has not disclosed how many accounts were compromised, how long the operation ran, or what the stolen tokens were subsequently used for — gaps that matter considerably given that Claude tokens represent direct access to one of the most capable AI systems currently available.
The timing is uncomfortable. Anthropic is competing at the highest level of an industry where trust in infrastructure is as commercially critical as model performance. A token-theft operation — however contained — signals that the attack surface around frontier AI platforms is being probed with increasing sophistication. Stolen tokens could be resold, used to run large-scale queries at another user's expense, or leveraged to extract outputs that the legitimate account holder would never have authorised.
Anthropic has not confirmed whether the vulnerability has been fully closed. For enterprise clients building pipelines on Claude, that silence is the detail that will matter most when security reviews come around. Per TechCrunch, the company is continuing its investigation.
*By Isla Camilleri, Global Affairs & Lifestyle Editor — News Beast by FreeMalta.com*