Info-Stealers Target Claude Accounts to Siphon Quotas via Unauthorized Tokens
First seen · 9/9/2026, 07:29 AMLatest activity · 9/9/2026, 07:29 AM
Attackers are leveraging off-the-shelf info-stealing malware to siphon expensive AI compute from unsuspecting developers. Anthropic confirmed that leaked session keys were used to mint unauthorized Claude Code OAuth tokens, effectively rerouting paid allowances—such as $200 monthly Claude Max tiers—to run tasks for dubious third-party services. Because the platform currently offers aggregate meters rather than granular audit logs, affected users only noticed the drain after zeroed-out quotas halted their daily workflows.
Event heat · last 24 hours
There are 7 persisted snapshots in the last 24 hours. Peak heat was 10 at 9/12, 17:00; latest heat is 10.