Stolen AI Session Tokens From Claude and ChatGPT Sold for $5 on Telegram
Cybersecurity researchers at FlashPoint analyzed nearly 45,000 stolen session tokens from a single infostealer log dump and found 555 belonging to AI platforms including Claude, ChatGPT, Gemini, and Copilot. Of those, 24 API keys remained valid at the time of analysis, each granting buyers full account access including conversation history, document uploads, and API usage. Anthropic confirmed in early September 2026 that session tokens harvested via browser-based malware were being actively sold and used against live Claude accounts, with no flaw in Anthropic's own infrastructure involved. Known malware families such as Lumma, Vidar, and Redline steal these tokens from users' machines in under 30 seconds, often through cracked software downloads or fake CAPTCHA pages. Buyers replay the stolen tokens using browser fingerprint-spoofing tools, bypassing two-factor authentication entirely and exploiting victims' accounts for large-scale AI compute operations known as LLMjacking.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in