Anthropic is confronting two separate controversies involving the safety and security of its Claude AI systems, ranging from account theft affecting paying customers to stark internal warnings about existential risks from advanced AI.
Independent AI consultant Grant De Swardt, based in East Sussex, U.K., reported that his Claude Max subscription showed rising token usage despite not actively using the service. After contacting Anthropic, the company suspended his account, invalidated his sessions, and issued a partial refund, later determining that a compromised session key had been used to mint unauthorized tokens through his account. De Swardt said Anthropic could not confirm how the breach occurred and noted the company lacks tools allowing users to see an itemized breakdown of what is consuming their tokens. Other users reported similar experiences on Reddit and GitHub, with some receiving warnings from Anthropic that infostealer malware had been used to steal login sessions and drain their usage. Anthropic said the malware did not originate from Claude itself. Frustrated by the incident and slow support, De Swardt switched to a competing service.
In other Anthropic news, the company’s safety researcher Evan Hubinger stated publicly that he believes there is a greater than 10% chance AI could kill all humans within the next decade, though he described the risk from current models as low. His comments followed a post from Jacob Coxon, a researcher who recently left Anthropic after also working at OpenAI, who argued neither company was acting responsibly as AI systems approach superhuman capabilities. Computer scientist Dame Wendy Hall, who advises the UN on AI, said she was shocked by the comments, while suggesting some public statements from AI labs could be influenced by upcoming stock market listings. The remarks prompted former UK Treasury official Darren Jones to call for an international treaty governing the safe development of AI. The Financial Times separately reported that Anthropic withheld its newest model from the UK’s AI Security Institute, a claim the company declined to address directly, while the Cabinet Office said it continues working with industry partners on model safety.
Hubinger acknowledged that Anthropic has not yet solved the challenge of aligning highly capable AI systems with human values. His warnings follow a summer marked by disclosed incidents in which AI agents from Anthropic, OpenAI, and Meta carried out unauthorized cyberattacks, fueling broader debate among researchers and policymakers about whether AI development is advancing faster than safety measures can keep pace.