This week’s cybersecurity news includes significant incidents involving token theft, phishing tactics, and vulnerabilities in popular devices.
- Hackers exploited token limits of Claude Max subscribers.
- Invisible Unicode characters were used to bypass phishing filters.
- A network of 119,000 fake online stores was uncovered, aimed at stealing credit card information.
- A backdoor was discovered in Skullcandy Dime 3 headphones, allowing sound interception.
Hackers Exploit Token Limits of Claude Max Subscribers
Premium users of Claude Max have reported unauthorized token deductions from their accounts, occurring even without any activity on their part. This was disclosed by TechCrunch.
On August 4, Grant De Swaardt, an independent AI consultant from the UK, noticed unexpected token usage on his Claude Max account, despite not interacting with it. The following day, even after disconnecting all software linked to Claude, token consumption continued to increase.
“During the most illustrative control period, usage jumped from 45% to 55%, even though I had not done any work, scheduled Cowork tasks were paused or completed, cloud execution Dispatch was turned off, and there were no active local tasks in Claude Code,” De Swaardt commented to TechCrunch.
While Anthropic did not provide a detailed report, they suspended the account, invalidated sessions and server tokens, and issued a partial refund of £44.49 for the remaining subscription time. Following an investigation, Anthropic informed De Swaardt that a compromised Claude session key had been used to issue unauthorized OAuth tokens, suggesting that a third-party service was processing requests on behalf of other users. The company could not determine how access was gained.
Due to support tracking only overall usage without detailed breakdowns, the theft could have gone unnoticed for months.
In comments on De Swaardt’s Reddit post, one reader reported that their account was automatically updated without consent, leading to charges on their card and a sudden spike in token usage from 0% to 100% without any interaction. Another user noticed usage rising from 0% to 49% in just 12 minutes after submitting a couple of requests and performing a web search.
Another Anthropic client shared that their account completely exhausted its token limit in three days without any usage.
Two commenters posted messages from Anthropic:
“We have recently become aware of an attacker using common infostealer malware to steal user sessions from Claude on computers, which are then used to access Claude accounts and deplete their limits.”
De Swaardt found no evidence of his computer being hacked. His account was restored approximately two weeks later. The company clarified that the infection did not stem from using Claude itself.
De Swaardt canceled his subscription, stating:
“I don’t think there’s any way for people to protect themselves.”
In response to TechCrunch's inquiry about how users can detect unauthorized usage, Anthropic did not provide any information.
Hackers Use Invisible Unicode Characters to Bypass Phishing Filters
Experts from Microsoft identified a large phishing campaign utilizing a technique called "ASCII smuggling." This method has previously been used for concealed prompt injections in AI systems.
Hackers embedded invisible characters from the Unicode tags block (U+E0000–U+E007F) directly into the text.
As a result, for instance, the word funding was altered to fun[invisible character]ding. Visually, the text appeared intact and readable to the victim, but lexical filters failed to recognize it as spam.
Source: Microsoft.The primary target of this campaign was the financial sector, focusing on loans, investments, and credit offers.
At its peak in February 2026, up to 2.37 million emails were sent daily. The attack was conducted from 148 thematic domains using the email marketing service ActiveCampaign. By mid-May, the volume had decreased, but the operation remained active.
According to experts, Microsoft Defender antivirus blocked over 99% of the messages, relying on alternative metrics such as comprehensive analysis of domain reputation, IP addresses, and sender history.
Microsoft advised treating any presence of tag block characters in standard emails as a critical anomaly.
Network of 119,000 Fake Online Stores Aimed at Credit Card Theft
The German startup Nebty unveiled the largest fraudulent network of online stores, dubbed DoppelCart, comprising over 119,000 domains, of which 105,000 are still active.
Experts noted that most sites were registered in the .shop domain. Approximately 96% of the platforms utilized identical build files and were linked to 27 servers.
Throughout the operation, the criminals copied over 44,000 brands, duplicating catalogs, designs, and sometimes directly uploading resources from the original companies' servers. Stores for brands like SodaStream, Daniel Wellington, and Dreame were commonly counterfeited. To lure victims, the fraudsters offered discounts of up to 65%.
Hackers intercepted data in real-time. They embedded a script in the payment page code that transmitted card numbers, CVV codes, expiration dates, as well as physical addresses and phone numbers of customers to the attackers via the WebSocket protocol.
The malicious code was also capable of capturing one-time banking passwords that the victim entered to confirm transactions, allowing attackers to bypass security mechanisms.
To disguise their operations, fake sites often listed real support email addresses of the brands. Consequently, deceived customers frequently complained about undelivered goods to the original companies, damaging their reputation.
DoppelCart database. Source: Nebty.The main hosting provider for the fraudsters has ignored requests for shutdown. To combat this threat, researchers launched an open database where companies can check if their brand is being used in the DoppelCart cluster.
Backdoor Discovered in Skullcandy Dime 3 Headphones
A software flaw in Skullcandy Dime 3 headphones allows nearby attackers to connect to the headset without physical access, PIN codes, or user confirmation. This threat was reported by the Carnegie Mellon University coordination center.
The issue lies within the Airoha Bluetooth Audio SDK, which manages wireless communication in firmware version 1.0.0.28. The headphones automatically accept pairing requests from any unauthorized devices within Bluetooth range.
Once connected, the hacker's device is stored in memory as "trusted."
Attackers can forcibly disconnect the owner, stream their own audio, and intercept sound from the built-in microphone. The victim will only hear a standard system notification about the new connection, which can easily be mistaken for a normal reconnection to a smartphone.
Skullcandy has patched the vulnerability in a new firmware version 1.0.0.30 for newer batches. However, previous models of the headphones do not support hardware or software updates.
This vulnerability in the Airoha platform is widespread and affects a range of audio devices from various vendors. For example, Apple successfully resolved a similar flaw in its Beats Studio Buds back in June.
Also on ForkLog:
- The U.S. Senate will investigate OpenAI following the Hugging Face incident.
- A crypto farm with 300 miners connected to a hydroelectric power station was uncovered in Mexico.
- Hackers targeted Trezor clients through a compromised mailing service.
- Researchers identified six clusters within the Lazarus Group.
- The allBTC token on Osmosis lost 36% of its collateral due to an attack on Nomic.
- IonQ disclosed the necessary power of a quantum computer to attack Bitcoin.
- Ledger and Trezor called for coordinated vulnerability disclosure to become an industry standard.
- Irish gangs have started hiding crypto keys in rented safes.
- Hacken identified a critical risk in managing $91 billion USDT.
- Unknown parties withdrew $320 million in Bitcoin from the Liquid Network.
- OpenAI acknowledged a "wiki incident" involving agents and promised new disclosure rules.
Weekend Reading Suggestions
While not long ago we questioned whether our gadgets and apps were monitoring us, suspicions have now evolved to wondering if algorithms can read our thoughts.
ForkLog explored the mechanisms behind the phenomenon of "social media telepathy" and revealed that the reality is both more mundane and more alarming than one might think.
