Dispatch
OpenAI Announces $200B Valuation Round   •   EU AI Act Compliance Deadline Extended to 2027   •   Google DeepMind Releases Gemini Ultra 3.0   •   Y Combinator S26 Batch: 60% of Startups Are AI-Native   •   MarTech Consolidation: Salesforce Acquires MadTech Pioneer   •   LLM Token Costs Drop 80% Year-Over-Year   •   Meta Llama 4 Released Under Permissive Commercial Licence   •   Anthropic's Claude Achieves New Benchmarks on Reasoning Tasks   •   Venture Capital Flows to AI Infrastructure Exceed $4B in Q2   •   Adobe GenStudio Reaches 500,000 Enterprise Users   •   OpenAI Announces $200B Valuation Round   •   EU AI Act Compliance Deadline Extended to 2027   •   Google DeepMind Releases Gemini Ultra 3.0   •   Y Combinator S26 Batch: 60% of Startups Are AI-Native   •   MarTech Consolidation: Salesforce Acquires MadTech Pioneer   •   LLM Token Costs Drop 80% Year-Over-Year   •   Meta Llama 4 Released Under Permissive Commercial Licence   •   Anthropic's Claude Achieves New Benchmarks on Reasoning Tasks   •   Venture Capital Flows to AI Infrastructure Exceed $4B in Q2   •   Adobe GenStudio Reaches 500,000 Enterprise Users
Est. MMXXV — Independent Digital PressWednesday, 17 September 2026Vol. I — No. 204
MarTech • Startups • LLMs • Digital Strategyterekhindigital.comMorning Edition

Terekhin Digital Media

Rigorous Journalism at the Frontier of Digital Commerce & Machine Intelligence

Wednesday, 17 September 2026Issue No. 204
LLMs

Hackers Are Draining Claude Max Accounts via Infostealer Malware — One User Lost 49% of Monthly Quota in 12 Minutes

Anthropic confirmed the attack vector: infostealer malware harvests saved Claude session credentials, generates unauthorised OAuth tokens, and burns through the victim's monthly usage allowance. Affected accounts suspended, sessions invalidated, partial refunds issued. No itemised usage logs provided. No new protective measures announced.

Multiple Anthropic Claude Max subscribers reported discovering that their monthly usage allowances were being consumed without any action on their part — one user's account moved from 0 per cent to 49 per cent used in twelve minutes. Anthropic investigated and identified infostealer malware as the attack vector: malicious software spread via infected software downloads and malicious advertising harvests saved Claude session credentials from infected machines and creates unauthorised OAuth tokens, which attackers then use to consume the victim's subscription quota. Anthropic has suspended affected accounts, invalidated compromised sessions, and issued partial refunds; the company declined to provide itemised usage logs or announce new protective measures. For practitioners running agent workflows or client projects through Claude subscription tiers, session credential theft is now a distinct threat category from API key compromise — the attack surface is the browser's saved credential store, not the application's secrets management. Recommended immediate steps: enable two-factor authentication on your Anthropic account, audit active OAuth applications in account settings, and set up anomaly alerts on usage dashboards. Unusual token consumption that cannot be explained by your own workflows should be treated as a potential compromise indicator, not an attribution error.

AnthropicClaudesecurityinfostealerOAuthsession credentialsAI securitymalware
← Return to Front Page
Related Articles
© MMXXVI Terekhin Digital Media — All Rights Reserved — An Independent Digital Publication