Workaholic Developers

No. 37

Today's briefing

Your AI Account Is Now Worth Stealing

Stolen Claude subscriptions, a heavy Microsoft patch cycle, and a maths claim under fire — plus what a sensible owner should actually do about any of it.

9 stories Sourced from TechCrunch, Ars Technica, Constellation Research, OpenAI and others
Abstract illustration accompanying Your AI Account Is Now Worth Stealing
Abstract illustration, generated with AI. It represents the idea, not the event.

The one that matters

Hackers are stealing Claude subscriptions — and your account holds more than you think

TechCrunch ↗

TechCrunch, followed by a second outlet, reports that criminals are stealing Claude access tokens from paying subscribers. A token is simply the string of characters that proves to the provider's servers that a request is coming from your paid account. Whoever holds it can spend your allowance without your password and without your knowledge. The published detail is thin, so treat the exact mechanism as unconfirmed — but the direction is clear enough to act on today.

What this actually means for your business

Two things, and the money is the smaller one. A paid seat runs roughly ₹1,700–2,000 or about C$30 a month, so a stolen seat is an irritation. A stolen API key on a usage-based account is different: it bills by volume, and someone reselling access can run up a bill for weeks before your card statement arrives.

The bigger problem is what is sitting inside the account. Since your staff started using AI, that login has quietly become the least-protected copy of your most sensitive documents. At a 600-student school, the office manager pasted the fee-defaulter list in to draft reminder letters. At a 30-bed clinic, the front desk pasted a discharge summary in to simplify the language for a patient. At a twelve-person agency, someone pasted a client contract in to summarise it. None of that went through your ERP or your accountant. It is in a chat history behind one password that one person chose, and possibly reused.

What it does not mean, and who will oversell it

Nothing in the reporting says the provider itself was broken into. Credentials of this kind usually leak from the customer side — a personal laptop carrying information-stealing malware, a key pasted into a WhatsApp group, an unofficial browser extension promising cheap or free access. It also does not mean AI tools are unsafe to use in a business; a stolen password for your accounting software would be worse.

Expect the overselling within a fortnight. Someone will pitch your 40-person workshop an AI security platform on a monthly subscription, citing this exact story. You do not need one. The controls that would have prevented this cost nothing and take an afternoon.

What to do this month

  • List every AI account the business pays for, including the ones staff bought on personal cards and expensed. This list is almost always longer than the owner expects.
  • Turn on two-factor authentication on each, and move them onto company email addresses rather than personal Gmail accounts. Thirty minutes.
  • Rotate every API key older than three months, and any key that has ever appeared in a chat, an email or a shared drive. Treat those as already public.
  • Set a hard monthly spend cap on any usage-based account. It converts a runaway bill into a small one.
  • Open the billing page and read last month's usage. Volume you cannot account for, or activity at odd hours, is the tell.
  • Give staff one rule in one sentence: nothing goes into a chat window that you would not hand to a stranger at the gate. If the work genuinely needs patient names, salary data or signed contracts, pay for the business tier and switch off training on your data.

That is the whole response. No new vendor, no new line item — just the same account hygiene you already apply to your bank login, applied to the tool your staff now paste everything into.

Also worth knowing

  1. Microsoft's patch batch this month is unusually heavy

    Ars Technica reports an outsized round of Microsoft security patches, framed as getting ahead of faster, AI-assisted attack tooling. This is boring and it matters: the realistic threat to a shop or clinic is still an unpatched front-desk PC, not a clever model. Schedule the reboots this week rather than next month.

    Ars Technica ↗
  2. Copilot Studio can now build small apps outright

    Microsoft added native app building to Copilot Studio, so a non-developer on a Microsoft 365 plan can assemble something small in-house — a leave request form, a stock check, a visitor log. If you already pay for Microsoft, spend an afternoon on it before commissioning a custom app for the same job. Assume the first two attempts get thrown away; that is normal and still cheaper.

    Constellation Research ↗
  3. ChatGPT's image tool gets better at working from your own sketches

    The update turns rough sketches and reference photos into finished images more reliably. Genuinely useful for menu boards, festival posters and catalogue mock-ups — the work a shop or agency currently sends to a freelancer a few thousand rupees at a time. It still will not replace a photographer for real product shots, and customers can tell the difference.

    OpenAI ↗
  4. Developers hit weekly ceilings after being promised 20x usage

    The New Stack reports paying developers running into weekly caps despite headline promises of far more usage; the same 5x and 20x claims are now the subject of a lawsuit. The lesson is not about one vendor — multiplier and 'unlimited' language in AI pricing is marketing, not a contract. Budget on your worst week, and pilot a tool for a full month before you standardise on it.

    The New Stack ↗
  5. LibreOffice sets download records by advertising no AI at all

    The free office suite hit download records after stating plainly that it has no AI features, and the announcement drew 645 points on Hacker News. That is a real market signal: a visible share of buyers now reads 'AI inside' as a reason to hesitate rather than upgrade. If your office suite renewal is going up purely for AI features nobody on staff asked for, it is fair to ask what you are paying for.

    Hacker News ↗
  6. OpenAI's big maths claim is already being disputed by mathematicians

    OpenAI published what it says is an AI-generated solution to the Navier–Stokes problem, unsolved for roughly 90 years and carrying a $1 million prize; mathematicians publicly contested the conduct and the credit, with one NYU academic accusing the company of fighting dirty. Nothing here touches your operations in any way. Keep it as a template: when a lab announces a breakthrough, wait for the field's response before changing a single plan.

    The Verge AI ↗
  7. A vendor case study claims 21% more engineering output

    OpenAI published a customer story saying 1Password's engineers gained 21% productivity using its coding tool. Read it as what it is — the vendor's own write-up of a software company with unusually strong engineering discipline, and one number with no method attached. If a supplier quotes that figure at you, ask what exactly was measured and over how long.

    OpenAI ↗
  8. Meta launches Muse, a personal AI agent

    Three outlets covered Meta's launch of a personal AI agent called Muse; substantive detail is still thin, so it is early to judge. Nothing to do about it this month. Do note the direction, though: within a year a fair number of your customers and staff will be running a general-purpose assistant on their phone, and it will be reading your website and your prices on their behalf.

    Hacker News ↗

How this briefing is put together

Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.

More editions

Published daily
A new edition every weekday morning, dated and kept permanently at its own address.
Every claim sourced
Each story links to the original announcement or report. Read them and disagree with us.
Written for owners
No benchmark scores or parameter counts — just what a development changes for a working business.

We use cookies

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. Learn more