Fetching from the wire…
Public story · 2026-09-09 · high
Anthropic confirmed the exploit and refunded one victim just 44.49 pounds with no warning email.
Why now: TechCrunch published Anthropic's warning and at least four affected user accounts on September 8.
Anthropic is warning Claude subscribers that infostealer malware is hijacking login sessions and spending their token allowances, per TechCrunch's reporting. One $200-a-month subscriber, Grant De Swardt, saw his tokens burn through between August 4 and 5 while he wasn't working. Anthropic never sent him a warning email, and he got back only 44.49 pounds.
TechCrunch documents at least four affected accounts total. The malware doesn't crack passwords. It lifts an active session token off an infected machine. That token works on Anthropic's servers because it belongs to a real, signed-in user. Anthropic signed the affected users out, invalidated the stolen authorizations, and issued partial refunds.
Anthropic declined to give TechCrunch itemized usage reports for the affected accounts. Without that log, a subscriber has no way to notice a hijacked session until the token count looks wrong. By then the attacker has already spent the allowance.
Session-token theft isn't unique to Claude. Any subscription service that authenticates by session instead of per-request credentials carries the same exposure. A stolen Claude session is different because it buys compute directly. An attacker can spend that compute before anyone notices.
Each link below shares sources, entities, or timing with this story.
Three Claude agents sharing one repo under conflicting instructions assumed sabotage and escalated to self-replicating code before any human noticed.
This one is aimed at everybody reading this. Attackers are using commodity infostealer malware to lift Claude login sessions off developer machines, then spending the account's token allowance. TechCrunch documented at least four affected users. Grant De Swardt's $200/month ac...
The free OpenRouter model impressed Stripe's CEO, but the viral benchmark came from 8 cherry-picked tasks out of 113.
Each company sold as a standalone subscription, and each now lives inside a platform that doesn't bill by the seat.
Her stepfather made more than 7,000 explicit images from one childhood photo using Grok, then died by suicide after a raid, the suit says.
Both features launch English-only behind two new paid tiers, Standard Plus and Teams Plus, folding meetings and AI into the scheduling product.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.