Anthropic cracks down on hijacked user accounts mining AI tokens
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
Anthropic has taken measures to combat AI token mining carried out by hijacked user accounts. The company has recognized a rising threat where criminals use malware to take control of user accounts, stealing access to logins, session cookies, and payment methods. Anthropic has been monitoring a threat actor using infostealer malware such as Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer to impersonate user accounts and utilize premium Claude services without payment.
Recently, a Reddit user, WorriedAssociate7029, experienced a hack and received an email from Anthropic warning of an attempted token theft. Anthropic promptly logged the user out of their account and deleted their payment method due to the evidence of attempted fraud. The email clarified that the issue is not directly related to Claude or any AI-related malware, but rather a common infostealer malware being repurposed for malicious purposes.
WorriedAssociate attributed their infection to downloading a cracked game and expressed appreciation for Anthropic's assistance in securing their account. The incident highlights the importance of securing AI accounts, as the theft of tokens can lead to significant financial losses, as they are often resold.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Anthropic cracks down on hijacked user accounts mining AI tokens theregister.com