黑客正在窃取订阅用户的 Claude Token
原标题:Hackers are stealing Claude tokens from subscribers
My Analysis of the Anthropic/Claude Security Incident
Okay, here's what I've got. I'm looking at a news snippet about a security issue with Claude, the AI platform by Anthropic. The first sentence hits me: "Last month, a Claude user noticed his account was consuming tokens even though he wasn't working." Right, so a user was seeing token consumption on their account, even when they weren't actively using the service. That immediately screams a potential security breach, likely unauthorized access. "Token consumption" in this context? Sounds like someone's either running something, or the system itself is malfunctioning in a way that's billing for usage.
Then the second sentence confirms the direction of my thought process: "Anthropic has since warned users about hackers." That's the confirmation. So, the issue is flagged as a direct security concern. My technical brain immediately goes into risk assessment: unauthorized access is likely the culprit; the question then becomes is this a supply chain attack (highly unlikely but possible) or is this user specific credential compromise (much more likely). It’s not necessarily a full-blown "hack" in the sense of a complete system takeover, but it's definitely a security incident, a compromise. They're telling users to be vigilant about potential malicious actors. It would be valuable to understand what steps Anthropic took, and if this was a widespread incident. This is all standard cybersecurity protocol.
上个月,一位 Claude 用户发现,尽管自己当时并没有在工作,其账户却在消耗 Token。此后,Anthropic 已就黑客风险向用户发出了警告。
为什么值得读
高额度推理配额正被黑客视作可直接变现的资产,提示团队与个人需立即排查会话安全与异常用量。