WorkSeptember 8, 2026via TechCrunch AI

Hackers are stealing Claude tokens from subscribers

Why it matters

A real security vulnerability affecting paying Claude users, with operational/deployment implications for enterprises relying on Claude APIs and subscriptions. This is a live threat practitioners need to account for in their security posture and access controls.

Key signals

  • Claude accounts being compromised to drain token balances without user action
  • Anthropic has issued formal warning to users
  • Incident first noticed by individual user detecting unauthorized consumption
  • Affects paid subscribers with token-based billing models
  • Security vulnerability in production affecting working practitioners
  • Claude user discovered unauthorized token consumption on his account
  • Anthropic issued warning to users about account compromise
  • Attack vector: token theft from active subscriber accounts
  • Timeline: discovery last month, warning issued by Anthropic
  • Impact: direct financial harm (token billing) and account security

The hook

Claude users waking up to drained token balances — Anthropic confirms account takeovers are real.

Last month, a Claude user noticed his account was consuming tokens even though he wasn't working. Anthropic has since warned users about hackers.

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.

Hackers are stealing Claude tokens from subscribers | KeyNews.AI