Claude token theft exposes a new AI security problem
Stolen Claude session credentials were used to generate unauthorised access tokens, highlighting a growing security risk around high-value AI accounts.

AI accounts are becoming valuable credentials in their own right — especially when they connect to code, files and business systems.
What happened
Anthropic investigated unexplained Claude Max usage on a customer account and found that a compromised Claude session key had been used to generate unauthorised Claude Code OAuth tokens. The credentials appeared to have been used by an unauthorised third-party service.
Why it matters
An AI credential can provide more than access to a chatbot. As agents gain permissions to repositories, documents and external tools, stolen tokens can potentially become a route into broader operational systems.
The bigger picture
Enterprise AI security is expanding from model safety into identity and access control. Companies will increasingly need to manage AI sessions, agent permissions and machine credentials with the same seriousness as privileged human accounts.
