Hacker bypassed 2FA with stolen cookies, Anthropic blocked token theft

WorriedAssociate7029 · reddit · 2026-08-29

After a user's social media was hacked, the attacker used stolen Chrome credentials (including cookies and session IDs) to bypass two-factor authentication. Anthropic detected and alerted the user to an attempt to steal tokens via the API, preventing the attack. The user revoked all Google sessions and reset passwords, highlighting that even strong security measures are vulnerable to simple cookie theft.

Original post →

More from Safety

Safety channel →