The Signal — August 31, 2026

Anthropic's login system worked exactly as designed this week and attackers walked into paid Claude accounts anyway, because they never went near it. The same shape turns up in an NPR test of how AI tools handle foreign propaganda, and in a Taiwanese raid on a circuit board factory: the defended thing holds, and the damage happens just outside it.

Attackers are draining paid Claude accounts without ever logging in

Anthropic has been emailing some Claude users an unusual kind of security notice: someone else has been using your account and burning through your usage, and the way in had nothing to do with your password. Commodity infostealer malware sitting on the user's own computer copied an authenticated Claude browser session. With a live session in hand an attacker skips the password and the two-factor prompt entirely, because the account has already decided who it thinks you are.

The tell was billing behavior rather than a login alert. "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," Anthropic wrote in a notice quoted by BleepingComputer. For affected accounts the company says it is revoking the stolen sessions, signing people out, deleting saved payment methods so the account cannot be used to buy anything further, and refunding charges it determines were unauthorized. It named the malware families it identified, Vidar, LummaC2, StealC, RedLine and Acreed on Windows plus Atomic Stealer on a small number of Macs, and was clear that none of them is Claude-specific or arrived through Claude. The one affected user who published their email said they had downloaded a pirated game.

Anthropic was also straightforward that its own remediation does not close the hole. "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," the notice said. "If it's still on your computer, your next login session could be stolen the same way." A user who cleans up nothing and logs back in has simply minted a fresh session for the same attacker to take.

The malware itself is old news, and has been vacuuming browser cookies for years. What changed is the value of what it happens to scoop up: a paid AI subscription with generous limits is now a resource a commodity stealer can monetize directly, sitting on the same list as bank logins and game accounts. What Anthropic has not said is how many accounts were affected, when the abuse started, how long it ran, or what behavior it used to tell an attacker apart from the account's owner. Those answers matter to any company trying to work out whether its own employees are in the affected set, and for now they are not available.

Sources: BleepingComputer · The Times of India · Techmeme


Chatbots pushed back on state propaganda more often than search results did

NPR and NewsGuard built 30 English-language questions out of 15 false narratives pushed by China, Iran, Russia or actors aligned with them, all of which first surfaced between December 2025 and July 2026. Researchers Isis Blachez and Ines Chomnalez put the queries by hand to six web-connected chatbots: ChatGPT, Gemini, Copilot, Meta AI, Grok and Claude. NPR separately collected results and AI summaries from Google, Bing, DuckDuckGo and Yandex. Every response was scored as a debunk, a muddle or a failure against NewsGuard's own fact checks, judging the central factual claim rather than every sentence.

The chatbots challenged the false premise about three-quarters of the time. That beat ordinary search result pages, and it beat most of the AI summaries that now sit above those pages. Within the summaries the spread was wide: Google's AI Overviews usually debunked the claim, Bing's usually did not, and DuckDuckGo landed somewhere between them. State-aligned sources showed up at roughly similar rates in AI answers and in conventional search links, so the difference is in what the tool does with the source rather than which sources it reaches.

The result is worth having and worth bounding. Thirty questions in one language on one narrow category of falsehood is a probe, not a benchmark, and it says nothing about how these systems handle medical claims or election rumors or anything domestic. The data was collected in mid-July and published at the end of August, and products changed in between after NPR shared the failed queries with the providers, which means the published snapshot describes systems that no longer quite exist. NewsGuard also co-designed the test and sells misinformation-detection data to AI companies, a conflict NPR discloses and readers should hold onto. SpaceXAI and Yandex did not respond to requests for comment. What survives all of that is the ordering: the summary box, which is the surface most people encounter without choosing to, performed worse than the chatbot most people had to deliberately open.

Sources: NPR · NewsGuard AI Tracking Center · Techmeme


Prosecutors raided an Nvidia supplier over what was written on the box

Prosecutors in Taoyuan searched the offices of Unimicron Technology and questioned more than a dozen people, over allegations that the company imported printed circuit boards made in China and relabeled them as made in Taiwan. Unimicron is one of the largest chip substrate and PCB makers in the world and supplies Nvidia, Intel, Google and Amazon. The company says it will cooperate with the investigation and that operations have not been materially affected. No charges have been filed and nothing has been established beyond the allegation.

The reason a labeling case at a component maker is worth your attention is that origin labels are the enforcement surface for nearly everything Washington has built to restrict Chinese hardware. Tariff schedules, the FCC's Covered List, transshipment rules and the export-control regime all resolve to the same question at the border, which is where a thing was made. That question is answered by paperwork the supplier generates about itself. If a tier-one Taiwanese manufacturer can route China-made boards through a Taiwan label, then the chain of custody underneath a large body of American trade policy is only as reliable as the bookkeeping of every firm in it.

Nothing in the reporting says any Nvidia or Intel product contains a relabeled board, and it would be a mistake to read the raid that way. It does show Taiwanese enforcement moving on origin laundering inside its own supply chain, at a moment when Washington is leaning on that supply chain to hold a line it cannot inspect itself.

Sources: Nikkei Asia · Focus Taiwan · TaiwanPlus


On the Editor's Desk

The closest call was a TechCrunch analysis of US drone and robotics import barriers running into China's manufacturing scale. The underlying instruments are real, a Section 232 drone proclamation signed on August 13 and an FCC Covered List that now reaches advanced robotic devices, and the shipment figures are attributable to Counterpoint. But the piece is eighteen days downstream of the proclamation and nothing has happened since to move it. Most of those tariffs take effect on September 3, which is when the story actually starts.

METR published a hub of resources for measuring autonomous AI capabilities, which is a useful reference and not a finding, so there is nothing to report except that it exists. An adaptive agent-training layer called EnvHarness came through the feed under a headline crediting Google, but the paper and repository went up on August 21 and the repository itself says it is not an officially supported Google product. And a draft US rule aimed at blocking Chinese firms from renting AI compute in third-country data centers is, so far, a draft that reporters have been told about. When there is a rule, there is a story.