2026-10-11 16:38 UTC

TechCrunch reports that hackers are stealing Claude subscribers’ tokens, potentially exposing subscription access to unauthorized use.

state: corroboratedheat: lowuncertainty: mediumconvergesscott: highagentic-security credential-securityAnthropicTechCrunch

What is this?

TechCrunch (Sep 8, 2026) reported that attackers are using infostealer malware to steal Claude subscribers' authentication sessions β€” grabbing browser cookies and active session keys rather than passwords β€” and using those keys to mint unauthorized Claude Code OAuth tokens that drain paid accounts before owners notice. A victim's GitHub report prompted an Anthropic investigation; warning emails (first reported by BleepingComputer Aug 30, circulating as unauthenticated copies) describe infostealers as the vector, with Anthropic revoking sessions, removing payment methods, and refunding victims β€” several secondary outlets characterize this as Anthropic confirmation, but no authenticated first-party statement is on record. A later Oct 7 self-published Warden telemetry post claims stealer logs are exfiltrating raw .claude.json API keys and OAuth tokens directly from developer machines, an independent but unverified observation consistent with the reported mechanism.

Why it matters to Scott

Converges: Warden telemetry showing stealer logs exfiltrating raw .claude.json primaryApiKey values and OAuth tokens moves the plaintext-credential complaint from storage-risk claim to observed in-the-wild theft, independently confirming the premise SiloOS/runtime-containment is built on β€” ambient host credentials on agent workstations are live attack surface β€” and it lands on his daily driver (Claude Code) and his documented shared-authenticated-browser-session practice. High rather than medium because it creates an action item (audit and rotate his own stored Claude credentials), strengthens the argument for his Nango-style brokered-credential pattern over plaintext-on-disk, and hands him a dated receipt for the 'scoped, minted, revocable keys instead of ambient secrets' thesis; the telemetry source is self-published, so the receipt is provisionally priced.
ip:framework.siloosdev:project.silo-osdev:technology.claude-codedev:concept.shared-authenticated-browser-sessionip:concept.runtime-containmentradar:claude-code-plaintext-oauth-tokensradar:concept.claude-coderadar:concept.credential-securityradar:concept.credential-isolationradar:concept.credential-theftradar:claude-artifact-macos-infostealer
queries asked of Scott's wikis
  • Claude Code credential storage and plaintext API key exposure
  • credential isolation practices for coding agent harnesses
  • shared browser session risk in authenticated agent workflows
  • OAuth token minting and delegated access in dev tooling
  • infostealer threat model for developer workstations
  • agent runtime secrets management in local environments

Measured heat

now 0 pts/hpeak 30 pts/hcomments 0/hpeers p37momentum: steady3 platformsage 1034h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

08-29 14:00⭐ origin echo-reconstructedThe primary artifact is an Anthropic warning email reproduced by a Reddit user. It says a bad actor used infostealer malware to steal Claude
Anthropic on x (echo) Β· attributed from hn.story.49639094
β€”
09-10 06:11first on hacker news Β· published Β· +280.2hHackers are stealing Claude tokens from subscribers
fourfire
β€”
09-10 13:18first on r/ClaudeAI Β· published Β· +287.3hIs someone stealing my tokens?
aredditor17
β€”
09-10 06:11amplified on hacker newshn.story.49639094
fourfire
peak 4 Β· 1 comments Β· 7% of case engagement
09-10 13:18amplified on r/ClaudeAIreddit.post.1wcizto
aredditor17
peak 2 Β· 7 comments Β· 7% of case engagement
09-11 18:21amplified on hacker newshn.story.49662941
gscott
peak 12 Β· 1 comments Β· 17% of case engagement
09-19 23:03amplified on hacker newshn.story.49770860
matt_hollins
peak 1 Β· 0 comments Β· 1% of case engagement
09-29 23:38amplified on r/ClaudeAIreddit.post.1wtpq7n
SaladTraining
peak 3 Β· 18 comments Β· 15% of case engagement
10-06 17:39amplified on r/ClaudeAIreddit.post.1wz8x7r
No_Security4822
peak 1 Β· 1 comments Β· 1% of case engagement
2 more amplifiers in ainews.case_chain
09-10 06:21our radar first saw it Β· +280.4hdiscovery anchor: hn.story.49639094β€”
pace: p57 vs 519 stories at the 720h mark (now 1034h old) β€” ahead of teleport-cross-harness-session-portability (1.0x), behind ai-agent-ransomware-operation (1.0x)

Evidence (9) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnHackers are stealing Claude tokens from subscribersfourfire41
🟧 echo.x ⭐The primary artifact is an Anthropic warning email reproduced by a Reddit user. It says a bad actor used infostealer malware to steal ClaudeAnthropicβ€”β€”
🟠 redditIs someone stealing my tokens?
ClaudeAI
aredditor1707
🟧 hnHackers are stealing Claude tokens from subscribersgscott121
🟧 hnClaudecookie – convert, check, and mint Claude Code credentials from a cookiematt_hollins10
🟠 redditDid anyone's free limit reset get used automatically?
ClaudeAI
SaladTraining318
🟠 redditUnexpected Claude Usage: 98% Under β€œOther
ClaudeAI
No_Security482211
🟠 redditInfostealers are actively hunting AI Agents and developer keys - Warden Infostealer analysis
ClaudeAI
Malwarebeasts21
🟧 hnHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksPicardManeuver308

Interpretation history

Decision trace