45
Search: “GitHub personal access tokens”
235 stories
55
30
60
57
57
60
45
60
45
45
42
30
30
57
60
57
42
57
57
42
60
30
42
30
60
45
60
60
55
45
60
30
60
45
30
57
60
57
Hackers are stealing Claude tokens from subscribers
Infostealer malware is stealing Claude login sessions, letting attackers mint OAuth tokens and burn subscribers' paid usage largely undetected.
Anthropic confirmed a bad actor used common infostealer malware to steal Claude login sessions from users' computers and consume their paid usage. A UK consultant saw idle token usage climb, and Anthropic suspended his account, invalidated sessions and Claude Code tokens, and issued a £44.49 partial refund on his $200-per-month plan. Multiple other users on Reddit and GitHub reported similar theft; Anthropic signed out affected users and issued refunds, but still lacks itemized usage reporting to help users detect misuse.
55