Lilith Lilith.
Editorial illustration: Hackers are stealing tokens to premium Claude accounts
Lilith illustration · editorial remix

Someone else's account available without knowing the password

A security flaw at Anthropic is allowing attackers to take control of paid Claude accounts, TechCrunch reports. Stealing access tokens means hackers bypass the need to know the password or defeat two-factor authentication. Once they have the token, the application considers them an authorized user until the token expires or is manually revoked.

Stolen API keys as a lucrative business

While password theft is common, the market for stolen access tokens for premium AI services is booming. This poses a risk for companies, because a stolen account not only generates costs for the attacker but also opens up access to conversation history, which often contains sensitive company data, source code, and internal strategic documents.

Security mechanisms are falling short of reacting

The real problem is not just the theft itself, but the lack of mechanisms to detect unusual behavior. If an account suddenly starts generating a massive amount of tokens from IP addresses halfway across the world, the provider should automatically terminate the session. But in many cases, this is clearly not happening.

The patience of enterprise customers will be tested now

It will now be crucial to watch how quickly and forcefully Anthropic reacts. Introducing stricter binding of tokens to specific devices, mandatory logouts upon geolocation changes, and a transparent communication line to affected users will show whether they can learn their lesson before they lose the trust of enterprise customers.

Lilith's verdict

You subscribe to advanced intelligence, but access to it is guarded by doors that can be opened with a copied key. If AI companies can't even protect their own access points, they can't promise to protect your enterprise data.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗