Anthropic is signing affected users out, stripping saved payment methods and issuing refunds after someone began pulling Claude cookies out of ordinary stealer logs and spending other people's quota.
Perspective Coverage
7 publishers
- Builder
- Builder 19%
- Operator
- Operator 72%
- Investor
- Investor 9%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
FlashPoint pulled 555 AI-service tokens out of a single 44,791-token stealer dump, 24 of them still valid, and five dollars is the Telegram bulk price because a copied session leaves the victim's own login working.
Reality
- Evidence22
- Adoption30
- Hype gap+45
- Incentives55
- Confidence28
Grant de Swardt watched his Claude Max 20x allowance climb on a day he did no work. He asked Anthropic for an itemized usage log, and what he got was a two-week suspension and a partial refund of £44.49.
Reality
- Evidence46
- Adoption40
- Hype gap+14
- Incentives55
- Confidence55
Vidar, LummaC2, RedLine and Atomic Stealer are pulling session material that authenticates without a login prompt, so the usual reset-and-enroll response can leave the intruder inside and spending the victim's paid usage.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+18
- Incentives44
- Confidence36
The company told affected customers by email, with nothing on its status page, and the only symptom on the user's side was usage that refilled and drained on its own. Watching that burn is now the account holder's job.
Reality
- Evidence40
- Adoption30
- Hype gap+12
- Incentives55
- Confidence45
A TechCrunch guide to spotting hacked AI accounts documents the gap: ChatGPT and Perplexity offer multi-factor authentication, Claude sends a link to your email and has no password at all.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence45