WorkSeptember 8, 2026via TechCrunch AI
Hackers are stealing Claude tokens from subscribers
Why it matters
A real security vulnerability affecting paying Claude users, with operational/deployment implications for enterprises relying on Claude APIs and subscriptions. This is a live threat practitioners need to account for in their security posture and access controls.
Key signals
- Claude accounts being compromised to drain token balances without user action
- Anthropic has issued formal warning to users
- Incident first noticed by individual user detecting unauthorized consumption
- Affects paid subscribers with token-based billing models
- Security vulnerability in production affecting working practitioners
- Claude user discovered unauthorized token consumption on his account
- Anthropic issued warning to users about account compromise
- Attack vector: token theft from active subscriber accounts
- Timeline: discovery last month, warning issued by Anthropic
- Impact: direct financial harm (token billing) and account security
The hook
Claude users waking up to drained token balances — Anthropic confirms account takeovers are real.
Last month, a Claude user noticed his account was consuming tokens even though he wasn't working. Anthropic has since warned users about hackers.