메뉴
BL
TechCrunch AI • 17일 전

해커들이 클로드 구독자들의 토큰을 훔치고 있다

IMP
7/10
핵심 요약

해커들이 인포스틸러(정보 탈취) 악성코드로 사용자들의 클로드(Claude) 로그인 세션을 훔친 뒤, 이를 이용해 구독자의 토큰 사용량을 몰래 소진시키는 사건이 다수 확인됐다. 앤스로픽(Anthropic)은 일부 사용자에게 경고 메일과 환불을 제공했지만, 계정 지원이 세부 사용 내역을 제공하지 않아 도난이 수개월간 감지되지 않을 수 있다는 문제가 드러났다.

번역된 본문

8월 4일, 영국 이스트서식스의 독립 AI 컨설턴트인 그랜트 데 스워드트(Grant de Swardt)는 자신의 Claude Max 20x 계정에서 이상한 일이 벌어지고 있음을 알아차렸다. 그날 그는 작업을 하지 않았는데도 토큰 사용량이 계속 늘어나고 있었다. 다음 날 그는 Claude에 연결된 모든 것을 비활성화하고 작업하지 않았다. 그런데도 토큰 소비는 다시 증가했다. "가장 명확히 통제된 구간에서는, 제가 아무 작업도 하지 않았고 예약된 Cowork 작업도 일시중지되거나 완료된 상태였으며, Dispatch/클라우드 실행도 비활성화되었고, 실행 중인 로컬 Claude Code 작업도 없었는데 사용량이 45%에서 55%로 증가했습니다"라고 그가 테크크런치에 말했다. 무엇이 그의 토큰 할당량을 잡아먹고 있었을까? 알 수 없었던 그는 앤스로픽에 세부 사용 내역 목록을 요청했다. 앤스로픽은 목록을 제공하지 않았지만 무언가 잘못되었음은 인정했다. 회사는 그의 유료 계정을 정지하고, 모든 세션과 서버 측 Claude Code 토큰을 무효화했으며, 월 200달러 구독의 남은 기간에 대해 44.49파운드를 부분 환불해 주었다.

그는 테크크런치에, 계정 정지가 그의 사업에 큰 타격을 주었다고 말했다. 그의 일은 중소기업이 에이전트를 설정하도록 돕는 것, 즉 일종의 외주 파견 엔지니어로, 이메일에서 구매 주문 데이터를 회계 소프트웨어에 자동으로 불러오는 작업 등을 지원한다. 개인 사업자인 그는 자신의 사업 전반에도 에이전트에 의존한다. 일상 행정 업무, 웹사이트 디자인, 코딩 등이다. "요즘은 모든 게 AI를 통해 돌아가니까요"라고 그는 말했다.

조사 후 앤스로픽은 데 스워드트에게 범인을 찾았다고 알렸다. 유출된 Claude 세션 키가 승인되지 않은 Claude Code OAuth 토큰을 발급하는 데 사용된 것이다. 회사는 그의 계정이 "타인의 활동을 처리하기 위해 승인되지 않은 것으로 보이는 제3자 서비스에 사용된 것으로 보이나, 어떻게 접근 권한을 얻었는지는 확인할 수 없다"고 말했다고 그가 전했다. "그들은 그 증거가 제가 모르는 사이에 자격 증명/세션 데이터가 탈취된 것과 일치할 수도, 계정이 외부 서비스에 연결된 것과 일치할 수도 있다고 했습니다." 즉, 해커가 데 스워드트의 계정에 접근해 그의 토큰을 은밀하게 빨아들이고 있었던 것이다. 계정 지원은 요청이 있어도 총 사용량만 추적하고 세부 사용 내역은 제공하지 않기 때문에, 이런 종류의 도난은 몇 달 동안 감지되지 않은 채 진행될 수도 있었다.

그는 자신의 경험을 레딧(Reddit)에 올렸고, 댓글 80개가 달리는 사이 자신만의 일이 아니라는 것을 알게 되었다. 한 사람은 자신의 계정이 "동의 없이 자동 업그레이드되었고, 신용카드에 결제가 됐으며, 건드리지도 않았는데 사용량이 0%에서 100%로 급등했다"고 주장했다. 다른 사람은 프롬프트 몇 번과 웹 검색만 사용했는데 12분 만에 사용량이 0%에서 49%로 늘어나는 것을 목격했다. 한 Claude 사용자는 전혀 사용하지 않았는데도 3일 연속 매일 최대 토큰을 소진했으며, 이에 대한 깃허브(GitHub) 리포트를 작성했다. 레딧 게시물과 마찬가지로 다른 사용자들도 그곳에서 유사한 경험을 공유했다. 그중 두 명은 앤스로픽이 토큰이 도난당하고 있다는 사실을 식별하고 경고해 준 이메일을 게시했다. 해당 이메일에는 "최근 흔한 인포스틸러 악성코드를 사용해 사람들의 컴퓨터에서 Claude 로그인 세션을 훔친 다음, 그 로그인 세션을 이용해 Claude 계정에 접근하고 사용량을 소모하는 악성 행위자를 인지하게 되었습니다"라고 적혀 있었다.

인포스틸러는 사용자의 컴퓨터에 설치되어 저장된 비밀번호, 세션 데이터, 로그인 자격 증명을 훔치는 악성코드다. 앤스로픽은 의심스러운 활동을 감지하면 사용자를 로그아웃시키고, 기존 승인을 무효화하며, 일부 환불을 진행하고, 악성코드에 감염되었을 수 있다고 경고했다. 회사는 또한 해당 악성코드가 Claude 사용 자체에서 온 것이 아니라고 밝혔다. 이런 악성코드는 감염된 소프트웨어 다운로드부터 감염된 광고 클릭까지 온라인의 다양한 경로로 감염될 수 있다. 앤스로픽은 데 스워드트에게는 그런 이메일을 보내지 않았다. 그는 자신의 컴퓨터가 침해당했다는 증거를 찾지 못했으며, 해커가 어떻게 접근권을 얻었는지 여전히 확인할 방법이 없다고 말한다.

원문 보기
원문 보기 (영어)
On August 4, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed something strange going on with his Claude Max 20x account. He hadn't been working that day, yet his token usage was climbing. The next day, he disabled everything he had attached to Claude and did not work with it. Token consumption again increased. "In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task," de Swardt told TechCrunch. What was eating up his token allowance? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn't provide one, but it agreed something was off. It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 for the remaining time on his $200-per-month subscription. The suspension wreaked havok on his business, he told TechCrunch. His job is to help small and mid-size businesses set up agents — a sort of forward-deployed engineer for hire — for tasks like automatically loading purchase-order data from emails into the accounting software. As a sole proprietor, he relies on agents throughout his whole business, too: daily admin tasks, website design, coding. "Like everything is just running through AI these days," he said. After investigating, Anthropic told de Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told him the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access," he told TechCrunch. "They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service." In other words, a hacker was able to obtain access to de Swardt's account and was covertly siphoning off his tokens. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could have gone on for months undetected. He posted his experience on Reddit and after 80 comments, he discovered he was not alone. One person claimed that their account "was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it." Another saw usage go from 0 and to 49 percent in 12 mins, when all they had used it for was a couple of prompts and web search. One Claude user said their account burned through its max tokens every day for three days without them using it at all, and created a Github report about it. Like with the Reddit post, others users shared similar experiences there, too. Two of them posted emails from Anthropic where the company had — to its credit — identified and warned them that their tokens were being stolen. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," the email read. Infostealers are a type of malware that installs itself on a user's computer and steals saved passwords, session data, and login-credentials. When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds and warned them that they may have malware. The company also said the malware didn't come from using Claude itself. Such malware can be picked up from many sources online, from downloading infected software to clicking on infected ads. Anthropic did not send de Swardt one of those emails. He insists he found no evidence that his computer was compromised, and says he still has no way of determining how hackers gained access. de Swardt's Claude account was reinstated after about two weeks. But the difficulty of getting speedy help for the matter, plus the lack of an itemized usage, soured him on Claude. He cancelled his subscription in favor of Cursor and its ability to use multiple models, including more affordable open-source options. In his experience, these other models work as well as Claude. "It's not that much different or better," he said, adding that he can't see going back "without them actually having resolved the issue in any way." He says Anthropic still lacks tools that allows users to see what's consuming their tokens. "I don't think there's any way that these people can protect themselves." When asked for information on how users can identify misuse, Anthropic declined to comment. Topics AI , Anthropic , TC When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Julie Bort Venture Editor Julie Bort is the Startups/Venture Desk editor for TechCrunch. You can contact or verify outreach from Julie by emailing julie.bort@techcrunch.com or via @Julie188 on X. View Bio October 13 - 15 San Francisco Don't miss out . The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era? REGISTER NOW Most Popular A secret new Elizabeth Holmes documentary stuns Telluride Connie Loizos TechCrunch Mobility: Tesla Cybercab hits the road — and a snag Kirsten Korosec Hikers rescued after using Google Gemini for planning Anthony Ha Feds launch investigation into Tesla's Cybercab deployment Sean O'Kane Kirsten Korosec Tesla is asking people if they want to buy and run Cybercab fleets Kirsten Korosec Norway considers ban on camera-enabled wearable ‘pervert glasses' Zack Whittaker Uber is laying off 10% of staff, or 3,300 people Ram Iyer