- Roko's Basilisk
- Posts
- The Switchboard Crime Returns
The Switchboard Crime Returns
Plus: Zuckerberg trusts the labs, Seoul won't slow down, Philadelphia fights back.
Here's what's on our plate today:
🧪 Anthropic warns subscribers that stolen sessions are draining their Claude allowances.
📰 Zuckerberg says labs self-police; Seoul refuses to slow down; Philadelphia fights data centers.
🧰 Three tools worth trying: Have I Been Pwned, Hudson Rock, Malwarebytes.
Let’s dive in. No floaties needed.

Put your brand in front of 250,000 tech decision-makers.
Bay Area Times reaches more than 250,000 founders, operators, investors, and venture capitalists, 90% of them in the United States, with a 53% open rate.
Native placements sit inside the editorial flow rather than beside it, so your message gets read with the news instead of scrolled past. Slack, Attio, and Granola have run here.
Placements range from a single secondary slot to a full newsletter takeover.
*This is sponsored content

Goodies delivered straight into your inbox.
Get the chance to peek inside founders and leaders’ brains and see how they think about going from zero to 1 and beyond.
Join thousands of weekly readers at Google, OpenAI, Stripe, TikTok, Sequoia, and more.
Check all the tools and more here, and outperform the competition.
*This is sponsored content

The Laboratory
TL;DR
A crime that targeted corporate cloud accounts for two years has now spread to individual subscriptions.
The origin: Sysdig named LLMjacking in May 2024, after attackers used stolen cloud logins to spend other people's model capacity.
The shift: in August, Anthropic began warning Claude subscribers that infostealer malware had taken their login sessions and was draining their allowance.
The cost: one consultant watched his allowance rise from 45% to 55% with no work running, and was suspended for two weeks before a £44.49 refund.
The counter: Anthropic says the malware was general-purpose and the Claude sessions were picked out later, while stolen access has resold for as little as $30 a month.
The stakes: subscribers cannot see what consumed their allowance, weekly limits fall again on September 14, and four suits over that metering may be grouped together.
Stolen AI compute has reached the individual subscriber
Through the 1990s, the most expensive thing a company could leave unlocked was its telephone system. Criminals dialed into corporate switchboards, found the internal line that allowed outside calls, and sold those calls on the street. The business that owned the switchboard learned about it weeks later, when a bill arrived listing every number dialed and nothing about who had dialed it. The trade later reached ordinary households through stolen calling-card numbers, turning one person's account into a resalable commodity. Nothing about the phone network had changed in between, since the crime had only found a new class of victim who paid a monthly bill and had no way to check what it was for.
Stolen artificial intelligence capacity has just completed the same journey. The crime is more than two years old, while the person absorbing the cost is new, and that move from a company's cloud bill to one subscriber's $200 monthly plan is the larger event here. It puts the loss on somebody with no security team and no itemized record.
Incidents of AI compute being stolen were first reported two years ago. At the time, Sysdig's threat researchers found attackers in May 2024 using stolen cloud logins to reach 10 hosted model services, Anthropic's among them, and named the practice LLMjacking, the consumption of somebody else's paid AI capacity at their expense. Sysdig's later work on reverse proxies found one reseller instance that ran close to $50k of charges through other people's accounts in about four and a half days. Pillar Security then traced a campaign it could attribute to a specific operator, this time working through exposed model and Model Context Protocol endpoints rather than stolen logins, with the marketplace reselling access at 40% to 60% below retail. By early 2026, the theft had become a supply chain, not just a technique. Last month it started landing on individual power users, the ones paying for the most generous plans.
Anthropic started writing to those users in August, saying infostealer malware had taken over their login sessions and was spending their Claude allowance, according to a notice BleepingComputer reported on August 30, 2026. TechCrunch published the fullest account yet of a named subscriber, Grant De Swardt, an independent AI consultant, on September 8, 2026. He shut down everything attached to his account and measured his usage, which climbed from 45% to 55% with no work running. He asked the company for an itemized breakdown of what had consumed it and did not receive one.
The stolen thing is a measured quantity of compute
A breakdown of that kind would have to be counted in 'tokens', the unit a model reads and writes, roughly a short word or part of one. Every request consumes them, and they cost real money because producing them requires computation on scarce hardware, which is why access to AIs is always rationed. Anthropic caps what a flat-fee subscriber may consume in a rolling five-hour window, with a weekly ceiling above that. Past the included limit, consumption continues at standard rates, billed to a saved card.
Signing in to that allowance and completing a two-factor check creates a small file called a ‘session cookie’, and anything holding that file is treated as the person who signed in. A copy of the file therefore works without the password. An 'infostealer' is ordinary criminal software that sweeps saved passwords and other files off a computer into a bundle sold on criminal markets.
A criminal who buys one of those bundles can generate a long-lived credential from it, which lets a separate program work through the account without a browser. That turns a stolen login into a service to rent out. The renting works through a middleman server: a paying customer sends a question to it, and the server passes that question to Claude using the stolen credential. The answer goes back to the customer, who never sees whose account paid for it.
Deleting the saved card shows what the theft reaches
Anthropic signed out the subscribers paying for that consumption when it detected the suspicious activity, deleted their saved payment methods, and refunded charges it deemed unauthorized. Signing users out addresses stolen capacity, while deleting the card addresses stolen billing, which is only possible because consumption past the plan limit runs onto a stored card. De Swardt's account was suspended for about two weeks, and when he canceled and moved to a competitor, he received £44.49 back for the unused remainder of the month, not for the capacity taken.
The allowance itself has also shrunk, since Anthropic said it could not secure enough compute to keep the temporary boost it extended through the summer. On September 14, 2026, it cut Claude Code weekly limits by 17%, a reduction it presented as a permanent 25% increase over the pre-May baseline.
Anthropic's own account argues that nothing new happened
However, while subscribers are only now discovering this form of theft, Anthropic has a very different story to tell. According to the company, the malware was general-purpose, already resident, and unrelated to Claude. Six commodity-stealer families were named, and the Claude sessions were selected from material collected for other purposes. If that account holds, the changed economics arrived after the theft rather than causing it.
Sysdig observed stolen access reselling at around $30 per month, a price that describes crowded, low-margin crime rather than a prized new asset. Attribution is weaker still, because De Swardt never received the infostealer notice, found no evidence his machine was compromised, and was offered two explanations without being told which one applied.
A drained allowance also has an explanation that involves no thief, since Anthropic conceded in April 2026 that its own engineering changes had degraded Claude Code for seven weeks and reset limits for every subscriber as compensation. That concession is now the premise of a proposed class action in California, one of four consumer suits the court has been asked to group together, over the objection of several of the plaintiffs involved.
Subscribers cannot see a per-session account of what consumed their allowance, the same record the lawsuits are asking for, which leaves three plausible causes for any drain: theft, unattended agents, and defects the vendor has already admitted. The old telephone bill listed every number dialed, which gave the victim a document to argue from. A Claude subscriber gets a percentage that rises, with nothing underneath it. On September 14 the ceiling on that percentage fell again for Claude Code, which will produce fresh reports of drained allowances and make each one harder to attribute. Nobody has said whether the people paying will ever see an itemized version of where the capacity went.


Thursday Poll
📊 A drained Claude allowance could be theft, your own agents, or a vendor defect. What fixes it? |

Hire smarter with Athyna, save up to 70% on salary costs.
Athyna connects you with top LATAM AI talent, fast!
Meet vetted professionals in as little as five days, without long, expensive recruiting cycles.
Save up to 70% on salary costs when hiring AI engineers, product leaders, and data scientists.
Get AI-assisted matching plus human vetting, so your shortlist is tight, and your interviews are worth it.
*This is sponsored content

3 Things Worth Trying
Have I Been Pwned: Free lookup that tells you whether your email appears in known breaches and stealer dumps, the first check before blaming the vendor.
Hudson Rock Cavalier: Free infostealer search that shows whether your machine or domain turns up in criminal logs, the exact material Anthropic says the sessions came from.
Malwarebytes Free: On-demand scanner built for commodity stealer families, worth running before you sign back in and hand over a fresh session cookie.

Quick Bits, No Fluff
Zuckerberg says labs police themselves: Meta's CEO argued that commercial pressure and legal liability already give every lab reason to train safely, pointing to Meta's own months-long delay shipping Muse.
Seoul refuses to slow AI down: South Korea's deputy prime minister said the country cannot afford to ease off, as Seoul chases a top-three position in global AI.
Philadelphia fights the data center boom: More than 100 residents rallied for a construction moratorium in a neighborhood still living with the fallout of a shuttered oil refinery.
Meme Of The Day

The Toolkit
Tabnine: AI coding assistant that runs privately on your stack, useful for teams that can't send code to public AI services.
Mirage: AI video generator that turns prompts or photos into cinematic clips with multimodal foundation models.
Writer: Enterprise AI writing platform with custom models trained on your brand voice.

Rate This Edition
What did you think of today's email? |





