Product1 distinct publisher3 min readUpdated
A TechCrunch guide to spotting hacked AI accounts documents the gap: ChatGPT and Perplexity offer multi-factor authentication, Claude sends a link to your email and has no password at all.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
TechCrunch published a guide on August 15, 2026 explaining how to check whether accounts on ChatGPT, Claude and Perplexity have been broken into [1]. In the process it documented an authentication gap that matters to anyone standardizing a team on Claude: ChatGPT and Perplexity offer multi-factor authentication, and Claude does not, because Anthropic sends a login link to your email address instead of asking for a password [2][3].
The absence is structural, not a setting someone forgot to switch on. According to the guide, Claude does not allow you to use passwords at all, so after an incident there is no password to change [4]. That leaves session termination as the only lever. Claude's active sessions live under your username, then Settings, then Account; you can hover over a session you do not recognise and log it out, or use "Log out of all devices" [5][6]. Then you log back in with your email address and the link that arrives in your inbox [7].
Follow that through and the recovery story ends where it started. Logging out every device removes the attacker's current sessions but changes no credential, so anyone who still reads the mailbox can request a fresh login link [8]. The security boundary around a Claude account is not the Claude account. It is the email account, plus every mechanism that can read it: forwarding rules, delegated mailbox access, a helpdesk that can reset mail passwords, a stolen session at the identity provider.
ChatGPT's flow is not immune to email either, but it has more surface to defend. Active sessions sit under Settings, then "Security and Login", then "Active Sessions", with per-device logout and "Log out all" [9]. Resetting the password means logging out, choosing "Forgot password", and entering a six-digit code that arrives by email before setting a new one [10]. Perplexity is weakest on detection: it does not show you where you are logged in, so the only response available is "Sign out of all sessions" under "All settings", followed by a login using an emailed six-digit code [11][12]. Two of the three platforms covered offer a second factor; one does not [13].
Worth noting what the guide does not cover: it describes consumer sign-in flows and does not describe any enterprise or single-sign-on alternative for these platforms [14]. If your organisation has one, that is the thing to verify before treating this as settled.
What to watch: whether Anthropic ships MFA or publishes an enrolment path that puts a second factor in front of Claude login, and whether Perplexity adds a session list so a rogue device can be seen rather than merely swept away. For teams already on Claude, the practical consequence is that the hardening budget belongs on the mail provider, and that mailbox compromise should be logged as Claude compromise in the incident runbook.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
TechCrunch published a guide, dated August 15, 2026, on how to tell whether accounts on AI platforms including ChatGPT, Claude and Perplexity have been hacked.
ChatGPT and Perplexity offer multi-factor authentication (MFA).
Claude does not offer MFA, because instead of asking for a password, Anthropic's chatbot sends a login link to the user's email address.
Claude does not allow users to use passwords at all, so there is no password to change.
In Claude, active sessions are found by clicking your username in the bottom-left corner, then Settings, then Account.
In Claude, hovering over an unrecognised session reveals three vertical dots that allow Log out or Terminate, and there is also a Log out of all devices option.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-publisher procedural walkthrough, no vendor confirmation
The factual core is highly specific and independently checkable by any user - exact menu paths, control labels and email-code flows for three platforms - which is stronger than typical secondhand reporting. But it rests on one publisher's observation of consumer UI at a point in time, with no vendor documentation, changelog or second outlet corroborating that Claude offers no MFA and no password, and UI paths of this kind change frequently.
No adoption or usage signal in cluster
The supplied material contains no releases, deployments, benchmarks, incident reports, pricing or licensing changes, and no usage or prevalence figures for account compromise on these platforms. Nothing in the cluster supports an adoption measurement and none should be inferred.
Framing outruns sourcing modestly
The underlying claims are accurately reported and the derived 'your inbox is the entire login' conclusion follows logically from a link-only login with no password to rotate. The overstatement is scope: the source documents only consumer browser flows, never confirms with Anthropic that no MFA or alternative sign-in exists, and supplies no evidence that this design has produced any actual account takeovers, so a categorical security verdict rests on a narrow procedural observation.
Evergreen service-journalism traffic incentive, no disclosed vendor stake
The source is an instalment in TechCrunch's ongoing account-security guide series, a format whose commercial value comes from durable search and referral traffic; that favours broad platform coverage and confident, actionable phrasing. Against that, the cluster shows no vendor sponsorship, affiliate offer, product being sold, or financial interest in ChatGPT, Claude or Perplexity, so distortion pressure is low-to-moderate rather than high.
Verifiable details, but one publisher and no adoption base
Confidence is capped by structure rather than quality: a single publisher, zero corroboration, no vendor statement, and no adoption dimension to triangulate against. The procedural claims are precise enough to be trusted for the date observed; the broader security conclusion is a reasonable inference that could be overturned by an undocumented enterprise or SSO path.
product
Perplexity's Airtel giveaway bought 56 million downloads. Now it has to bill them.1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
security
The nationalization argument is really a vendor-continuity memo1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 15, 2026