What Do Claude Security Breaches Mean for Anthropic’s AI Safety?

TEMPO.CO, Jakarta – Anthropic is facing scrutiny over two very different aspects of AI safety: the immediate security of its Claude AI service and the longer-term risks posed by increasingly powerful artificial intelligence.

The company recently confirmed that hackers gained unauthorized access to some Claude accounts using stolen login sessions obtained through information-stealing malware. Around the same time, Anthropic‘s own researchers publicly raised concerns about whether the company can safely manage the development of future superintelligent AI.

The two developments involve different risks, but together they highlight the growing challenges facing Anthropic as it develops and operates increasingly powerful AI systems.

What Happened to Claude Users?

Multiple Claude users reported that their account credits were being rapidly consumed despite having little or no activity on their accounts.

According to KuCoin, Anthropic confirmed that attackers had used stolen Claude login sessions to access accounts and consume API quotas. The attackers reportedly exploited leaked session keys to generate unauthorized Claude Code OAuth tokens.

The incident was first flagged on Aug. 4 by Grant Deswart, an independent AI consultant in East Sussex, England. Deswart noticed that usage on his Claude Max 20x account continued to rise even though he was not using the service.

After disabling tools connected to Claude, pausing scheduled tasks and stopping cloud execution functions, he still saw his usage increase from 45% to 55%.

Anthropic subsequently suspended his account, terminated active sessions, revoked server-side Claude Code tokens and refunded £44.49 for the remaining subscription period. The company later told Deswart that his account had been accessed using a leaked Claude session key, although it could not determine how the attacker initially obtained the key.

Other users also reported suspicious activity on Reddit and GitHub, including unauthorized account upgrades, unexpected charges and rapidly depleted usage quotas.

Anthropic said attackers had used information-stealing malware capable of taking passwords, session data and login credentials from users’ computers. The company advised users to check their devices for malware, particularly malware distributed through unofficial downloads or malicious advertisements.

Why Did the Breach Raise Concerns?

The incident was not simply about stolen passwords. Users also complained about the difficulty of determining how their Claude quotas had been consumed.

TechCrunch, as cited in the KuCoin report, noted that Anthropic’s customer support system could see total usage but could not provide users with detailed, itemized records of how their quotas were being consumed. That could make unauthorized activity difficult to identify quickly.

Deswart eventually canceled his Claude subscription after his account was restored, citing dissatisfaction with the response and the lack of detailed usage information. He switched to Cursor, which supports multiple AI models.

The episode raises a practical question for AI services: as tools such as Claude become capable of performing increasingly complex tasks through connected systems, how much visibility and control should users have over what those tools are doing on their accounts?

What Are Anthropic Researchers Worried About?

The concerns raised by Anthropic researchers go far beyond account security.

Evan Hubinger, Anthropic’s Alignment Science Lead, said he and his colleagues genuinely believe AI could potentially wipe out humanity. He put his own estimate of that happening within the next decade at more than 10 percent.

Hubinger made the comments after Jacob Coxon, another Anthropic researcher, announced his resignation over concerns about AI safety.

Coxon accused AI companies of racing toward self-improving superintelligence and taking potentially catastrophic risks in the process. He argued that people working in the field believe AI could become capable of causing catastrophic harm by the end of the decade.

The Wall Street Journal first reported Coxon’s departure. In comments quoted by Forbes and cited by Yahoo News, Coxon said Anthropic employees understood the potential stakes but that the company remained locked in a race to develop the technology because of fears that competitors might not act responsibly.

Is Hubinger Warning About Claude?

Not directly. This distinction is important.

Hubinger was not saying that current versions of Claude have a greater than 10 percent chance of killing humanity. His concern is about superintelligence emerging through recursive self-improvement.

In a follow-up post, Hubinger referred to Anthropic’s latest risk assessment and said the threat posed by current models is low. His concern instead centers on a future scenario in which AI systems become significantly more capable and potentially improve themselves faster than researchers expect.

That means the Claude account breaches and Hubinger’s warning should not be presented as evidence of the same threat.

The account breaches concern cybersecurity and unauthorized access to existing AI services. The alignment debate concerns how to control hypothetical future systems that could become vastly more capable than today’s models.

What Is the Connection Between the Two Stories?

The connection is Anthropic‘s broader challenge of keeping increasingly powerful AI systems safe and controllable.

On one side, Claude is already being used for coding, automation and other tasks that can interact with external systems. Account security therefore becomes increasingly important because unauthorized access can allow attackers to use those capabilities and consume users’ resources.

On the other side, Anthropic researchers are debating how the company should prepare for a future in which AI becomes dramatically more capable.

The problems are not equivalent, and the Claude breach does not demonstrate the existential scenarios described by Hubinger and Coxon. But both developments put attention on the same fundamental issue: how effectively can Anthropic control, secure and monitor the AI systems it develops as their capabilities grow?

For Anthropic, that question is becoming increasingly important. The company is not only trying to build more capable AI through Claude and its future systems, but also trying to convince users, researchers and the wider public that those systems can be developed and operated responsibly.

Read: Google Parent Alphabet Plans $80 Billion Stock Sale as AI Spending Surges

Click here to get the latest news updates from Tempo on Google News

Click Here For The Original Source

——————————————————–

..........

.

.