黑客正在盗取订阅用户的Claude令牌。

qimuai 发布于 阅读:42 一手编译

黑客正在盗取订阅用户的Claude令牌。

内容来源:https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/

内容总结:

英国东萨塞克斯郡的独立人工智能顾问格兰特·德·斯瓦特日前遭遇了一场离奇的“AI账户盗刷”事件。8月4日,他发现自己并未使用Claude Max 20x付费账户,但令牌消耗量却持续攀升。次日,他停用了所有关联工具并暂停工作,消耗量仍从45%增至55%。在联系Anthropic公司后,对方虽未提供明细账单,但承认账户异常,随即暂停其服务、作废所有会话并退还44.49英镑部分费用。

作为协助中小企业部署AI代理的独立承包商,德·斯瓦特的业务完全依赖该账户处理日常管理、网站设计和编程任务。此次封禁让他陷入瘫痪。调查结果显示,黑客利用被盗的Claude会话密钥生成未授权OAuth令牌,导致第三方服务在用户不知情的情况下消耗其配额。由于平台仅统计总使用量而无单项明细,此类盗用可能持续数月而难以察觉。

德·斯瓦特将经历分享至Reddit后,多位用户反映类似遭遇:有人账户在未经同意下自动升级并产生扣费;有人在仅执行简单指令后,12分钟内使用率从0飙升至49%;甚至有人连续三天在完全未操作的情况下耗尽全部令牌。部分用户收到的Anthropic警告邮件指出,黑客正通过“信息窃取恶意软件”获取用户登录会话,该软件可窃取电脑中保存的密码和会话数据。Anthropic虽已对受影响用户进行登出、授权作废和退款处理,但未向德·斯瓦特发送此类预警,且其电脑未检出恶意软件痕迹。

经历两周波折后,德·斯瓦特虽恢复账户,但毅然取消订阅,转而使用Cursor及可接入包括开源模型在内的多模型服务。他认为其他模型性能与Claude相当,且“Anthropic尚未真正解决问题,用户缺乏自我防护手段”,因为平台始终未提供查看具体消耗来源的工具。截至发稿,Anthropic拒绝就用户如何识别账户异常操作作出回应。

中文翻译:

8月4日,英国东萨塞克斯郡的独立AI顾问格兰特·德·斯瓦特注意到自己的Claude Max 20x账户出现了异常。他当天并没有工作,但令牌使用量却在不断攀升。

第二天,他停用了所有关联到Claude的工具,并未使用它工作。令牌消耗再次增加。“在最清晰的受控时段内,使用量从45%升至55%,而我没有进行任何工作,预定的Cowork任务已暂停或完成,Dispatch/云执行已禁用,也没有相应的本地Claude Code任务在运行,”德·斯瓦特告诉TechCrunch。

是什么在消耗他的令牌额度?他一头雾水,于是联系了Anthropic,要求提供逐项明细清单。Anthropic没有提供明细,但承认确实有异常情况。该公司暂停了他的付费账户,使其所有会话及服务端Claude Code令牌全部失效,并就其每月200美元订阅的剩余时间发放了44.49英镑的部分退款。

他告诉TechCrunch,账户被暂停给他的业务造成了严重破坏。他的工作是帮助中小型企业搭建智能体——一种按需雇佣的前沿部署工程师——用于例如自动从电子邮件中提取采购订单数据并录入会计软件等任务。

作为个体经营者,他的整个业务也都依赖智能体:日常行政工作、网站设计、编码。“如今好像一切都靠AI在跑,”他说。

经过调查后,Anthropic告诉德·斯瓦特,他们找到了罪魁祸首:一个被入侵的Claude会话密钥被用来生成了未经授权的Claude Code OAuth令牌。公司告诉他,该账户“似乎被一个看似未经授权的第三方服务用来处理其他人的活动,但他们无法确定该服务是如何获得访问权限的,”他告诉TechCrunch。“他们说证据既可能指向在我不知情的情况下凭据/会话数据被窃取,也可能指向账户被连接到了外部服务。”

换句话说,有黑客获取了德·斯瓦特账户的访问权限,正在暗中窃取他的令牌。由于账户支持系统只追踪总用量而不追踪逐项明细——即便用户提出要求也是如此——这种盗窃可能持续数月而不被发现。

他将自己的经历发布在Reddit上,在收到80条评论后,他发现并非只有他一个人遇到这种情况。有人声称自己的账户“在我未经同意的情况下被自动升级,信用卡被扣款,使用量在我完全没碰的情况下从0%自动飙升至100%”。另一个人看到使用量在12分钟内从0升至49%,而他们只是用了几次提示和一次网络搜索。

一位Claude用户表示,自己的账户连续三天在完全不使用的情况下每天耗尽最大令牌额度;此人随后在GitHub上创建了一份相关报告。和Reddit帖子一样,其他用户也在那里分享了类似经历。

其中两人贴出了Anthropic发来的邮件——值得肯定的是,公司在这封邮件中识别并警告他们令牌正在被盗。

“我们最近得知有一名恶意行为者正在使用常见的信息窃取型恶意软件,从人们电脑上窃取Claude登录会话,然后利用这些登录会话访问Claude账户并消耗其使用额度,”邮件中写道。信息窃取器是一种恶意软件,它会安装在用户电脑上,窃取已保存的密码、会话数据和登录凭据。

当Anthropic发现可疑活动时,会让用户退出登录,使现有授权失效,发放部分退款,并警告他们电脑上可能装有恶意软件。

公司还表示,该恶意软件并非来自使用Claude本身。此类恶意软件可能通过许多网络渠道被感染,从下载被感染的软件到点击被感染的广告。

Anthropic并没有给德·斯瓦特发送这些邮件中的任何一封。他坚称没有发现自己的电脑被入侵的证据,并表示至今仍无法确定黑客是如何获得访问权限的。

德·斯瓦特的Claude账户大约两周后恢复使用。但此事难以获得及时帮助,再加上缺乏逐项用量明细,让他对Claude失去了好感。他取消了订阅,转而使用Cursor及其多模型支持功能,其中包括更实惠的开源选项。

根据他的经验,这些其他模型的表现与Claude不相上下。“并没有太大的区别或优势,”他说,并补充说他看不到回头的可能,“除非Anthropic真正以某种方式解决了这个问题。”

他表示,Anthropic仍然缺乏让用户查看是什么在消耗令牌的工具。“我认为这些用户没有任何办法自我保护。”

当被问及用户如何识别滥用行为时,Anthropic拒绝置评。

英文来源:

On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange going on with his Claude Max 20x account. He hadn’t been working that day, yet his token usage was climbing.
The next day, he disabled everything he had attached to Claude and did not work with it. Token consumption again increased. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt told TechCrunch.
What was eating up his token allowance? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn’t provide one, but it agreed something was off. It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 for the remaining time on his $200-per-month subscription.
The suspension wreaked havok on his business, he told TechCrunch. His job is to help small and mid-size businesses set up agents — a sort of forward-deployed engineer for hire — for tasks like automatically loading purchase-order data from emails into the accounting software.
As a sole proprietor, he relies on agents throughout his whole business, too: daily admin tasks, website design, coding. “Like everything is just running through AI these days,” he said.
After investigating, Anthropic told De Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told him the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access,” he told TechCrunch. “They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.”
In other words, a hacker was able to obtain access to De Swardt’s account and was covertly siphoning off his tokens. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could have gone on for months undetected.
He posted his experience on Reddit and after 80 comments, he discovered he was not alone. One person claimed that their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another saw usage go from 0 to 49% in 12 minutes, when all they had used it for was a couple of prompts and a web search.
One Claude user said their account burned through its max tokens every day for three days without them using it at all; this person then created a GitHub report about it. Like with the Reddit post, other users shared similar experiences there, too.
Two of them posted emails from Anthropic where the company had — to its credit — identified and warned them that their tokens were being stolen.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email read. Infostealers are a type of malware that installs itself on a user’s computer and steals saved passwords, session data, and login credentials.
When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds, and warned them that they may have malware.
The company also said the malware didn’t come from using Claude itself. Such malware can be picked up from many sources online, from downloading infected software to clicking on infected ads.
Anthropic did not send De Swardt one of those emails. He insists he found no evidence that his computer was compromised and says he still has no way of determining how hackers gained access.
De Swardt’s Claude account was reinstated after about two weeks. But the difficulty of getting speedy help for the matter, plus the lack of an itemized usage, soured him on Claude. He cancelled his subscription in favor of Cursor and its ability to use multiple models, including more affordable open source options.
In his experience, these other models work as well as Claude. “It’s not that much different or better,” he said, adding that he can’t see going back “without [Anthropic] actually having resolved the issue in any way.”
He says Anthropic still lacks tools that allow users to see what’s consuming their tokens. “I don’t think there’s any way that these people can protect themselves.”
When asked for information on how users can identify misuse, Anthropic declined to comment.

TechCrunchAI大撞车

文章目录


    扫描二维码,在手机上阅读