Reports have emerged regarding unauthorized access and the theft of authentication tokens by third parties on Claude, the AI platform developed and provided by Anthropic. Incidents have occurred where malicious attackers seize session information stored in users' browsers or PCs to gain unauthorized access to accounts.
This incident is not related to a product update, but rather a warning concerning malicious activity exploiting security vulnerabilities. Attackers are targeting authentication tokens stored locally on user devices. By utilizing these tokens, they are able to bypass the normally required password input and multi-factor authentication (MFA), making it possible to impersonate legitimate users.
Like many web services, Claude retains authentication credentials as tokens on the device to enhance user convenience. Attackers employ methods to physically acquire this information via malware or similar means. This is not a vulnerability unique to generative AI platforms, but rather a common type of attack targeting session management in modern web applications.
AI companies, including Anthropic, are urged to strengthen their security measures. On the user side, it is strongly recommended to strictly refrain from downloading suspicious software, regularly clear browser sessions, and keep browser and PC security settings constantly up to date.