Skip to content

Product1 publisher3 min readPublished

Claude has no MFA, so your inbox is the entire login

A TechCrunch guide to spotting hacked AI accounts documents the gap: ChatGPT and Perplexity offer multi-factor authentication, Claude sends a link to your email and has no password at all.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Claude has no MFA, so your inbox is the entire login
Generated illustration

What happened

  • TechCrunch published a guide, dated August 15, 2026, on how to tell whether accounts on AI platforms including ChatGPT, Claude and Perplexity have been hacked.
  • ChatGPT and Perplexity offer multi-factor authentication (MFA).
  • Claude does not offer MFA, because instead of asking for a password, Anthropic's chatbot sends a login link to the user's email address.
  • Claude does not allow users to use passwords at all, so there is no password to change.
  • In Claude, active sessions are found by clicking your username in the bottom-left corner, then Settings, then Account.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

TechCrunch published a guide on August 15, 2026 explaining how to check whether accounts on ChatGPT, Claude and Perplexity have been broken into [1]. In the process it documented an authentication gap that matters to anyone standardizing a team on Claude: ChatGPT and Perplexity offer multi-factor authentication, and Claude does not, because Anthropic sends a login link to your email address instead of asking for a password [2][3].

The absence is structural, not a setting someone forgot to switch on. According to the guide, Claude does not allow you to use passwords at all, so after an incident there is no password to change [4]. That leaves session termination as the only lever. Claude's active sessions live under your username, then Settings, then Account; you can hover over a session you do not recognise and log it out, or use "Log out of all devices" [5][6]. Then you log back in with your email address and the link that arrives in your inbox [7].

Follow that through and the recovery story ends where it started. Logging out every device removes the attacker's current sessions but changes no credential, so anyone who still reads the mailbox can request a fresh login link [8]. The security boundary around a Claude account is not the Claude account. It is the email account, plus every mechanism that can read it: forwarding rules, delegated mailbox access, a helpdesk that can reset mail passwords, a stolen session at the identity provider.

ChatGPT's flow is not immune to email either, but it has more surface to defend. Active sessions sit under Settings, then "Security and Login", then "Active Sessions", with per-device logout and "Log out all" [9]. Resetting the password means logging out, choosing "Forgot password", and entering a six-digit code that arrives by email before setting a new one [10]. Perplexity is weakest on detection: it does not show you where you are logged in, so the only response available is "Sign out of all sessions" under "All settings", followed by a login using an emailed six-digit code [11][12]. Two of the three platforms covered offer a second factor; one does not [13].

Worth noting what the guide does not cover: it describes consumer sign-in flows and does not describe any enterprise or single-sign-on alternative for these platforms [14]. If your organisation has one, that is the thing to verify before treating this as settled.

What to watch: whether Anthropic ships MFA or publishes an enrolment path that puts a second factor in front of Claude login, and whether Perplexity adds a session list so a rogue device can be seen rather than merely swept away. For teams already on Claude, the practical consequence is that the hardening budget belongs on the mail provider, and that mailbox compromise should be logged as Claude compromise in the incident runbook.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories