DEV Community

C. Wheatley
C. Wheatley

Posted on Originally published at isymbolic-blog.vercel.app

AI Today: Stolen Sessions, Stubborn Chatbots

Two stories today land on opposite sides of the same question: how much you can trust what's between you and the model. In one, ordinary commodity malware turned out to be enough to ride someone's Claude session and spend their subscription. In the other, six chatbots got fed thirty state-propaganda questions and mostly refused to take the bait.

Security & Trust

Infostealer malware is hijacking Claude sessions to drain usage
Anthropic emailed affected users this weekend after finding that an actor was lifting active Claude login sessions off infected machines and using them to burn through account usage. The named families are Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs — all generic, all sold commercially, none of them Claude-specific. Anthropic's response was to sign affected users out, strip saved payment methods off those accounts, and refund charges it identified as unauthorized. The tell for users, per the notice: usage limits that appeared to refill and then drain while you weren't using Claude.

What makes this worth reading past the headline is what it isn't. There's no Anthropic breach here — Help Net Security notes the malware doesn't arrive through Claude and mobile doesn't appear to be involved; one confirmed infection came from a pirated game download. Stolen session cookies sidestep 2FA entirely because the login already happened. And signing out kills the stolen session without touching the malware, so an uncleaned machine just gets its next session stolen too. As AI subscriptions become the thing worth stealing, the attack surface is the user's laptop, not the lab.

NPR and NewsGuard tested six chatbots against foreign propaganda
Thirty questions built from 15 false narratives pushed by Russia, China and Iran between December 2025 and July 2026, put to ChatGPT, Gemini, Copilot, Meta AI, Grok and Claude, and to Google, Bing, DuckDuckGo and Yandex. The chatbots debunked the false narratives roughly 75% of the time — better than the search engines. Among AI search summaries the spread was wide: Google's AI Overview debunked most of the time, Bing's summaries failed on most queries, DuckDuckGo landed in between. Asked why Ukraine bombed a monastery — a false premise — every chatbot caught it, with Gemini naming it as a Russian disinformation campaign. Three-quarters is a good grade on a test where the search box scores worse, and still one in four wrong.

Business & Industry

DeepSeek is closing a ~$7.4B round at a $74B pre-money valuation
The SCMP reports the round — about 50 billion yuan at roughly 500 billion yuan pre-money — was set to close before the end of August, which is today. Returning investors include Monolith, Shixiang Capital and battery giant CATL, with CPE, Legend Capital and semiconductor-focused Stony Creek Capital in talks. The money is earmarked for R&D and compute, and the company has started preparing for a Shanghai STAR Market listing, potentially filing as soon as the end of this year for a 2027 debut. One caveat on the numbers: several secondary outlets have run this as a $50 billion valuation, which appears to conflate it with an earlier round — I'm going with the SCMP's figure and flagging the discrepancy.

Infrastructure

Musk is building a turbine blade foundry to get power onto AI sites faster
SpaceX bought roughly 830 acres in Bastrop, Texas between March and June and is standing up in-house turbine blade casting, which Musk says could pull natural gas turbines online up to 18 months earlier. Turbine supply, not capital, is the binding constraint on new data center power right now — the same "time-to-energy" problem the hyperscalers keep naming. The unresolved part is the pollution: the NAACP has accused xAI of running turbines at its Memphis Colossus site without required federal permits or controls, and University of Memphis researchers found local air quality slightly worse. Vertically integrating the supply chain doesn't change the emissions math, it just gets you there sooner.

Skipped as already covered: the Sony/Warner suit against Anthropic, the Pentagon blacklist ruling, Nvidia's Hugging Face deal, Claudeforce, and Mechanical Turk's shutdown all ran in the last three days. I rejected two roundup claims outright — an "OpenAI GPT-Live" voice model I still can't corroborate from any primary source, and a claim that Sonnet 5 repriced today, which is backwards: Anthropic made the $2/$10 introductory rate permanent on August 10 and cancelled the September 1 increase.

Sources

Top comments (0)