Lookonchain APP

App Store

Claude Quota Mysteriously Drained? Hackers Begin Stealing Login Sessions, Even 2FA Can’t Stop Them

1 hours ago

Beating AI News: Anthropic is sending security alerts to select Claude users after the company discovered hackers stealing Claude login sessions from malware-infected devices to access accounts and deplete user quotas. Users on Reddit have already shared screenshots of the alert emails they received. Unlike stolen passwords, the compromised assets are already-authenticated browser sessions, which let attackers impersonate users directly without re-entering passwords or completing two-factor authentication (2FA). One affected user noted they logged in via Google and had 2FA enabled, yet their browser cookies and session IDs were still stolen together. Anthropic named several information-stealing trojans in the email, including Windows-based Vidar, LummaC2, StealC, RedLine, Acreed, and Mac-based Atomic Stealer (AMOS). These are all malware designed to steal browser cookies, passwords, and other data, not security flaws in Claude itself. The user added they had previously downloaded pirated software, which likely led to the infection. Anthropic said it has terminated detected suspicious login sessions, removed saved payment methods from affected accounts, and resolved related unauthorized charges. The company also emphasized that changing passwords alone will not fix the issue—if malware on the device is not removed, newly generated login sessions may still be stolen.

Relevant content

Zhipu AI’s revenue surges fivefold in six months: APIs serve as its absolute main revenue source, though the firm still posts a net loss of nearly 2 billion yuan.

Beating AI Express: Zhipu AI has released its first semi-annual report since listing. First-half revenue reached 954 million yuan, up 399.7% year-on-year, nearly five times the level of the same period last year. Growth was mainly driven by its open platform and API business: revenue in this segment surged from 29.1 million yuan to 825 million yuan, a year-on-year jump of 2735.7%, accounting for 86.5% of total revenue. Zhipu’s revenue structure has almost reversed: the open platform and API business (charged per call) rose from 26.3% of total revenue in the whole of last year to 86.5% this period, while localized deployment dropped from 73.7% to 13.5%. The gross profit margin of its API business also improved from -0.4% in the same period last year to 24.6%, with Zhipu citing expanded call volume, price adjustments, and lower inference costs as key reasons. However, R&D investment and losses remain high: first-half R&D expenditure hit 2.131 billion yuan, up 33.6% year-on-year; adjusted net loss stood at 1.964 billion yuan, expanding 12.1% from 1.752 billion yuan in the same period last year. Meanwhile, overall gross margin fell from 50.0% to 26.4%, mainly due to the rapid shift in revenue toward cloud-based business that is still in its growth phase.

9 minutes ago

ChatGPT to Face Tougher EU Cybersecurity Regulation

The European Commission said Monday that OpenAI’s ChatGPT will have to comply with stricter EU rules, such as removing illegal content, or face potential fines. Meanwhile, Brussels is working to clarify how its existing digital regulatory framework applies to rapidly evolving artificial intelligence services. The Commission noted that ChatGPT, social media forum Reddit, and gaming platform Roblox will be classified as so-called “very large online platforms” (VLOPs) under the EU’s Digital Services Act (DSA), the bloc’s landmark digital regulatory regime. This designation means the three services will bear additional obligations, including removing illegal content and protecting minors’ privacy and safety; non-compliance could lead to fines of up to 6% of their global revenue. The decision marks a further expansion of DSA oversight into the generative AI sector. Earlier, X’s AI chatbot Grok was already under investigation under the same law.

9 minutes ago

DeepSeek Releases Its First Open-Source Vision Model

Beating AI Insight News: DeepSeek has open-sourced the weights of DeepSeek-V4-Flash-Vision-Exp. This experimental vision model is built on V4-Flash, adding image comprehension capabilities that enable it to process screenshots, read charts, and complete agent tasks by integrating tools. It maintains performance on par with V4-Flash for pure-text agent tasks. Previously, the model was only accessible via API; developers can now download its weights to deploy it independently.

9 minutes ago

Gemini wins arbitration, cleared of liability for the collapse of its Earn lending program.

According to CNBC, cryptocurrency platform Gemini secured a legal victory in August, with an arbitrator ruling that the exchange did not mislead users and was not liable for the collapse of its Earn lending program. The lawsuit was filed by a user of the Earn lending program in late 2024. The ruling found insufficient evidence to prove Gemini lied to customers or was negligent in its due diligence of its primary lending partner, Genesis Global Capital. Launched in 2021, the Earn program allowed users to earn annual returns of up to 7.4% by lending out their cryptocurrencies. Under the program, Gemini lent assets to institutional borrowers with Genesis acting as an intermediary. However, Gemini suspended withdrawals from the Earn program in November 2022, angering some of its over 300,000 users. The move came shortly after Genesis paused new loans and redemptions amid a liquidity crisis triggered by the 2022 crypto market downturn. Following the Earn withdrawal freeze, multiple customers filed legal complaints against Gemini. The New York Attorney General also sued Gemini over the Earn program, and reached a $50 million settlement with the company in 2024. In February 2024, Gemini announced it had reached a "principal settlement" with Genesis and other creditors in Genesis' bankruptcy case. Three months later, Earn users received $2.18 billion in digital assets in kind, equivalent to 97% of the total digital assets owed to Earn users — $1 billion more than the amount available when Genesis suspended withdrawals in 2022.

9 minutes ago

CodexHost open-sources, integrating Claude Code, Pi, and Grok into the Codex desktop.

Beating AI Express News: Open-source project CodexHost has transformed Codex Desktop into a multi-agent workspace. It currently supports Codex, Claude Code, Pi, Oh My Pi, Grok Build, and DeepSeek Harness, allowing users to create and manage sessions for different agents within a single window. Codex Desktop is solely responsible for the unified interface, while each agent runs on its own harness—for example, Claude Code continues to use Agent SDK/CLI, and Pi retains its own RPC. CodexHost integrates these agents into Codex, preserving native capabilities such as tool calls, code diffs, approvals, and queries. Different agents can also assign tasks to each other: when Codex is writing code, users can separately launch Claude Code for code review, enabling parallel work between the two, after which Codex processes the results. This means multiple coding agents can be scheduled simultaneously within one Codex window. Installing CodexHost does not modify the official Codex or replace Codex CLI. Directly opening Codex Desktop or running Codex CLI in daily use bypasses CodexHost, which only takes effect when launched via CodexHost.

9 minutes ago

Zhipu’s revenue rose 399.7% year-on-year in the first half of 2026, with an adjusted net loss of 1.964 billion yuan.

Dongcha Beating AI Newsflash: Zhipu (02513.HK) announced that it generated revenue of RMB 954 million in the first half of 2026, a year-on-year increase of 399.7%, while its adjusted net loss for the period stood at RMB 1.964 billion. Among the total revenue, the open platform and API business contributed approximately RMB 825 million (around USD 123 million), surging 2735.7% year-on-year.

9 minutes ago

Popular tokens

BitcoinEthereumHyperliquidSolanaTRONBNBTetherAaveXRPPepeFartcoinOndoJupiterUniswapBonkPendleEthenaArbitrumAvalancheLidoChainlinkPolygonDogecoinCardano