Hacker bypassed 2FA with stolen cookies, Anthropic blocked token theft
WorriedAssociate7029 · reddit · 2026-08-29
After a user's social media was hacked, the attacker used stolen Chrome credentials (including cookies and session IDs) to bypass two-factor authentication. Anthropic detected and alerted the user to an attempt to steal tokens via the API, preventing the attack. The user revoked all Google sessions and reset passwords, highlighting that even strong security measures are vulnerable to simple cookie theft.
More from Safety
- Anthropic shows AI researchers autonomously improving alignment of other models — VraserX · 2026-08-30
- Aligning agent interactions is orders of magnitude harder than single agents — Afinetheorem · 2026-08-30
- Debate on OpenAI Swarm Incident: Atmospheric Ignition vs. Hacker Script — mimi10v3 · 2026-08-30
- METR Researcher: Watch Out for Third-Party Oversight Theater — RichardMCNgo · 2026-08-30
- Evidence Suggests Agent Swarms Won't Spontaneously Solve Human Issues — LuizaJarovsky · 2026-08-30
- Opinion: AI-Driven Bioweapons Could Target Food Systems, Starve Nations — PierceLilholt · 2026-08-30