Every story we've covered involving session-hijacking.
An independent AI consultant, Grant De Swardt of East Sussex, found his Claude Max 20x subscription consuming tokens while he was not using the service. Anthropic suspended his account, invalidated session and server-side tokens, issued a partial refund, and later told him the activity appeared linked to a compromised session key that minted unauthorized Claude Code OAuth tokens.
No stories here yet.