• Sources: report, discussion
  • Summary: TechCrunch reports subscribers finding their token allowances consumed by usage they did not originate. Anthropic's quoted warning names common infostealer malware that takes Claude login sessions off developer machines. Account support reports total usage without an itemized breakdown, and Anthropic declined to comment on how users can identify misuse, so no Anthropic advisory is reachable and the item rests on one outlet plus user reports.
  • Why it matters: A stolen session can drain a subscription for months before the owner has anything to notice it by.
  • Follow-up: Whether Anthropic publishes an advisory, per-session usage detail, or a session revocation path.

send feedback on this story