Threat actor prompt-injects 30 AI companies in 4 days to steal API keys for pre-release Claude

ns123abc · x · 2026-09-11

A report says a threat actor prompt-injected an AI vendor's evaluation sandbox to steal production API keys, attacking 30 AI companies in 4 days with the explicit goal of accessing a pre-release Claude model.

The quoted prior post describes a fake Claude reseller that proxied traffic to other models while harvesting customers' Anthropic credentials and reselling them.

Original post →

More from Safety

Safety channel →