行业新闻

黑客窃取 Claude 订阅用户令牌,Anthropic 已介入处理

Claude 订阅用户的 token 正被黑客通过窃取会话密钥悄悄消耗,Anthropic 已承认并采取应对,提醒用户检查本机安全。

英国独立 AI 顾问 Grant De Swardt 发现自己的 Claude Max 20x 账号在未使用时 token 消耗量仍持续攀升。Anthropic 调查后确认,恶意行为者通过 infostealer 恶意软件(一种窃取浏览器保存密码和会话数据的木马)窃取登录会话,再生成未授权的 OAuth 令牌消耗用户配额。由于账号仅显示总用量,用户很难察觉,多起类似案例已出现在 Reddit 和 GitHub。

正文摘录

On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange going on with his Claude Max 20x account. He hadn’t been working that day, yet his token usage was climbing. The next day, he disabled everything he had attached to Claude and did not work with it. Token consumption again increased. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt told TechCrunch. What was eating up his token allowance? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn’t provide one, but it agreed something was off. It suspende…

阅读原文(techcrunch.com)→

行业新闻Julie Bort2026-09-08原文

相关内容