Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

Hackers steal Claude compute credits from subscribers

Hackers are stealing Claude compute credits to run their own AI queries, shifting costs to unsuspecting subscribers. This theft highlights how paid AI access has become a valuable financial asset forโ€ฆ

Hackers are stealing Claude tokens from subscribers
TechCrunch โ€” 8 September 2026
Text:
1 0 0

Hackers are quietly draining cryptocurrency and compute credits from Anthropicโ€™s Claude subscription accounts, a problem that has forced the AI company to issue urgent security warnings to its user base. The issue came to light last month when a diligent user noticed his account was consuming tokens at an alarming rate despite him not actively using the service. This unauthorized usage indicates a breach of account security where malicious actors are tapping into paid subscriptions to run their own artificial intelligence queries. Anthropic has since confirmed the threat and advised users to take immediate steps to secure their credentials, marking a significant escalation in the security challenges facing consumer AI platforms. The incident highlights a growing vulnerability in the ecosystem of paid AI tools, where access to powerful models like Claude represents a tangible financial asset that cybercriminals are eager to exploit for their own computational needs.

This surge in token theft is not an isolated anomaly but rather a direct consequence of the immense value that AI compute has assumed in the current digital economy. Running large language models requires significant processing power, which translates directly into operational costs for developers and researchers. By stealing active subscriptions, hackers can bypass these costs, effectively laundering their computing expenses through the accounts of unsuspecting paying customers. The rise of AI-powered services has created a new black market for API keys and account credentials, similar to how credit card data has been traded for years. As more businesses and individuals migrate to paid tiers to access faster response times and larger context windows, the incentive for attackers to compromise these accounts grows exponentially. The technical sophistication required to automate the draining of tokens has also decreased, allowing even less skilled cybercriminals to deploy scripts that monitor and exploit weak or reused passwords across multiple platforms.

The financial and operational implications of this trend are becoming increasingly difficult for users to ignore. For individual subscribers, the loss is primarily monetary, as they are charged for usage they did not authorize. For enterprises relying on Claude for critical workflows, the breach of account security could lead to data leaks, where sensitive business information is processed by unauthorized third parties under the guise of legitimate queries. Anthropicโ€™s response has included stricter monitoring of unusual usage patterns and recommendations for users to enable two-factor authentication and rotate their API keys frequently. Industry experts suggest that this is likely the beginning of a broader wave of attacks targeting AI infrastructure, as the demand for compute resources outpaces the supply of affordable, legitimate access. Users are being urged to treat their AI credentials with the same level of caution as their banking information, recognizing that a compromised account is not just an inconvenience but a potential vector for larger security breaches.

Looking ahead, the battle between AI providers and cybercriminals is expected to intensify as the value of artificial intelligence continues to rise. Anthropic and other major AI developers are likely to implement more robust verification mechanisms, such as biometric authentication and real-time fraud detection systems, to protect user accounts. However, the cat-and-mouse game of cybersecurity ensures that attackers will continuously adapt their methods to bypass these new defenses. For consumers, the lesson is clear: passive security measures are no longer sufficient. Proactive account management, including regular password changes and vigilant monitoring of usage statistics, has become an essential part of using modern AI tools. As the AI market matures, the security of user accounts will likely become a key differentiator between providers, with those offering the strongest protections gaining a competitive edge in a landscape rife with digital threats. The incident serves as a stark reminder that in the age of artificial intelligence, your access keys are just as valuable as your money.

Read Full Story at TechCrunch โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Japan's Financial Services Agency plans blockchain system fโ€ฆ
๐Ÿ’ป Technology
Japan's Financial Services Agency plans blockchain system for faster securities settlemenโ€ฆ
CoinTelegraph ยท 13 days ago
Tech Life
๐Ÿ’ป Technology
Tech Life
BBC Technology ยท 14 days ago
Lenovoโ€™s first Android handheld lets you stream PC games wiโ€ฆ
๐Ÿ’ป Technology
Lenovoโ€™s first Android handheld lets you stream PC games without a network connection
Android Authority ยท 13 days ago
Lori Loughlin files for divorce from Mossimo Giannulli afteโ€ฆ
๐ŸŒ World News
Lori Loughlin files for divorce from Mossimo Giannulli after nearly 30 years
NBC News ยท 5 hours ago
Nigeria's jet fuel conundrum: Scarcity at home, abundance aโ€ฆ
๐ŸŒ World News
Nigeria's jet fuel conundrum: Scarcity at home, abundance abroad
DW World ยท 14 days ago
Firms scramble for battery power in Spain and Portugal
๐Ÿ’ฐ Business
Firms scramble for battery power in Spain and Portugal
BBC Business ยท 14 days ago
Full view