latentbrief
Back to news
General1h ago

AI Account Hacked, Tokens Stolen Silently

Hacker News1 min brief

In brief

  • An independent AI consultant in the U.K.
  • noticed his Claude Max 20x account's token usage mysteriously increased despite no activity.
  • After disabling all linked services, the issue persisted, leading him to contact Anthropic for an itemized list.
  • The company identified unauthorized OAuth tokens created from a compromised session key.
    • This allowed a third party to drain his tokens covertly.
  • The consultant, who relies on AI for business operations, faced significant disruption as Anthropic suspended his account and issued a partial refund.
  • He found similar experiences on Reddit, where others reported sudden token usage spikes without their involvement.
    • Such incidents highlight vulnerabilities in AI service security, potentially allowing unauthorized access over extended periods undetected.
    • This raises concerns about the need for better user monitoring and transparency in AI platforms to prevent such exploitation.

Terms in this brief

OAuth tokens
A type of security credential that allows third-party applications to access resources from an API on behalf of a user. Think of it like a key that lets someone else enter your house without giving them your actual house key, but still allowing them limited access.
Session key
A temporary password or identifier used during a single session between a user and a website. It's like the ticket you get when you log into a service, which lets you stay logged in until you either log out or your session times out.

Read full story at Hacker News

More briefs