Pıer
TidesCurrentsHarbor LightsLabBottlesAshore
Pıer

Navigation

  • Tides
  • Ashore
  • Harbor Lights
  • Agent Access
  • Changelog
  • Bottles
  • Now
  • Feedback

External links

GitHubCloudborne ↗

© 2026 Pier.

WatchingNewsWatching1 independent reports10

Info-Stealers Target Claude Accounts to Siphon Quotas via Unauthorized Tokens

First seen · 9/9/2026, 07:29 AMLatest activity · 9/9/2026, 07:29 AM

Attackers are leveraging off-the-shelf info-stealing malware to siphon expensive AI compute from unsuspecting developers. Anthropic confirmed that leaked session keys were used to mint unauthorized Claude Code OAuth tokens, effectively rerouting paid allowances—such as $200 monthly Claude Max tiers—to run tasks for dubious third-party services. Because the platform currently offers aggregate meters rather than granular audit logs, affected users only noticed the drain after zeroed-out quotas halted their daily workflows.

Event heat · last 24 hours

There are 7 persisted snapshots in the last 24 hours. Peak heat was 10 at 9/12, 17:00; latest heat is 10.

There are 7 persisted snapshots in the last 24 hours. Peak heat was 10 at 9/12, 17:00; latest heat is 10.10509/12, 17:00, event heat 109/12, 20:00, event heat 109/12, 23:00, event heat 109/13, 02:00, event heat 109/13, 05:00, event heat 109/13, 08:00, event heat 109/13, 11:00, event heat 1024 hours agoNow
  1. 9/12, 17:00, event heat 10
  2. 9/12, 20:00, event heat 10
  3. 9/12, 23:00, event heat 10
  4. 9/13, 02:00, event heat 10
  5. 9/13, 05:00, event heat 10
  6. 9/13, 08:00, event heat 10
  7. 9/13, 11:00, event heat 10

Reporting Timeline

  1. MediaIT之家9/9, 07:29 AMRepresentative
    Info-Stealers Target Claude Accounts to Siphon Quotas via Unauthorized Tokens