Hackers steal Claude session keys to burn Max subscribers’ tokens
TechCrunch reports infostealer malware is lifting Claude login sessions so attackers can mint Claude Code OAuth tokens and drain Max quotas, with Anthropic warning some victims and issuing refunds. Users say there’s still no itemized usage view to spot the theft early.
