Anthropic subscribers got a nasty story today: attackers are lifting Claude session tokens straight off people’s machines and reselling the access as discount API capacity. Not a breach of Anthropic’s infrastructure. Just credentials, sitting in files, on laptops, quietly waiting to be worth something to somebody.

The advice that follows a story like this is always identical. Rotate, enable 2FA, check your usage dashboard for spikes you didn’t cause. Fine, do all of that. But rotation is a mop, and I’d rather talk about the leak.

Rotate the key, and then what

Your credential got taken because it existed somewhere you’d stopped thinking about. That’s almost always the shape of it. Nobody’s Claude token gets stolen out of Anthropic’s vault; it gets stolen out of a config file, a shell history, a stale Docker layer, a proxy’s environment block, a note in Obsidian from the day you set it up.

So the number that matters isn’t how strong the credential is. It’s how many copies of it exist.

Count your copies

Sit down and actually enumerate. Where does your Claude key or session live right now? There’s the official app. Then probably a CLI config in your home directory. Maybe an .env in two or three repos, one of which you haven’t opened since March. Maybe a self-hosted proxy so your team can share a pool. Maybe a secrets manager for the cloud agent you spun up in April and never turned off. Maybe a vendor dashboard for whichever browser-automation service you were evaluating.

That’s six or seven independent places, each with its own attack surface, its own patch cadence, its own employees. A session token that only ever exists in one place, on one machine, under one operating system account, is a boring target, and the reason it’s boring is that stealing it requires already being on your laptop, at which point you have much larger problems than your Claude bill.

Credentials breed like paperwork. Every convenience you add copies them one more time, and the copies never get cleaned up, because deleting a working key feels like breaking something.

The math is unglamorous

Two copies of a credential isn’t twice the risk of one. It’s the risk of one, plus a vendor’s incident response process you’ve never read, plus somebody’s unpatched laptop in a city you couldn’t find on a map.

LiteLLM already ran this experiment

When the LiteLLM proxy breach hit, the lesson people took away was “audit your proxy.” The actual lesson was that an AI proxy is a liability by construction, because its entire job is holding everyone’s keys in one place and forwarding requests. Centralizing credentials is the product. Breaching it is just using the product from the wrong side.

And the same architecture keeps shipping under new names.

Everyone wants to run your browser for you now

This week alone brought autoscaling browser agents, Yamak’s open-source launch, and a fresh leaderboard ranking cloud agents against each other. All of them run Chrome on their hardware. So you paste your API key into their dashboard, or worse, you log into Gmail inside a Chrome instance running on somebody else’s hardware, and now a live authenticated session for your primary identity sits in a datacenter you will never physically visit.

That’s a hell of a lot more exposure than a stolen Claude token, and it doesn’t even show up as a breach headline, because you volunteered.

One machine, one copy, and you can watch it

This is the part I’m opinionated about. A browser agent should run in the browser you already use, with the login state you already have, using a key that never leaves your machine. That’s why dassi sits in the Chrome side panel instead of a server rack. Bring your own key and it stays in local browser storage. Or skip the key entirely and log in with your existing Claude or ChatGPT subscription, which means there’s no long-lived API credential to steal in the first place.

The other half is visibility. When dassi clicks through a page, you’re looking at the page. A cloud agent’s screenshot stream is a report about what happened, and reports can be wrong, or late, or absent. Cloud browser agents can’t see your tabs, and you can’t see theirs.

None of this makes you unhackable. Somebody with code execution on your laptop wins regardless. But there’s a real difference between one machine you control and seven vendors you’re trusting to have a good quarter, security-wise.

Anyway. Go check that .env from March.