Infostealers stole Claude sessions. SB Energy handed OpenAI $5.5 billion in warrants.
Anthropic is signing some Claude users out and wiping saved cards after consumer malware on their PCs copied live login cookies. SoftBank’s power and data-centre arm granted OpenAI warrants now worth about $5.5 billion to keep the tenant, then aims a $5-7 billion IPO. OpenAI is quietly testing pay-when-it-works with some large accounts. Online Risk Labs estimates Temu put as much as $962 million into Meta partnership ads that boosted mostly fake creators. Apple dropped Mac mini and Studio early after the labs treated the boxes as training iron.
In this Brief
- Infostealers stole live Claude cookies; Anthropic signs out, wipes cards, refunds. The malware stays
- SB Energy: ~$5.5B warrants to keep OpenAI as tenant, then a $5-7B IPO
- OpenAI testing outcome pricing with some large accounts. Terms unknown
- Temu: ORL estimates ~$962M on Meta partnership ads; 73 of the top 100 creators likely fakes
- Apple sold the Mac mini as a desktop. The labs bought it as a rack.
Signing out does not kill the malware.
Setup: BleepingComputer has Anthropic warning some Claude users that infostealer malware on their PCs stole active Claude login sessions, letting attackers access accounts and consume usage. Mayank Parmar, Sunday. The company is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorized.
Anthropic, in an email a user posted to Reddit: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” Symptom: “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”
Infostealers can copy an already-authenticated browser session. The attacker may not need the password or 2FA again. Anthropic says it has no reason to believe the malware is related to Claude, installed through Claude, or related to anything the user did with Claude.
Typical path: unofficial downloads or malicious apps. Named families: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs.
“Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.”
Security Affairs has the same email. Pierluigi Paganini, Monday. Phones and tablets “do not appear to have been involved.” Existing plans continue until the current billing period ends, then the user must re-add a card. Anthropic may sign out again if it detects more suspicious activity.
Take: This is not a Claude breach. The malware was already on the PC. It copied a cookie the browser had already logged in, so the attacker never had to type a password or pass a second factor. Anthropic can revoke the session and refund the card.
The named families are general-purpose stealers. The Claude session was one item in the haul. A Redditor who posted the email said they downloaded a pirated game. That is one machine, not a victim count.
Last weekend’s Claude Code limit change was product pricing. This is session-cookie theft. No count of accounts. No total drained.
The landlord paid the tenant to stay.
Setup: Anissa Gardizy at the Wall Street Journal reports that OpenAI was issued warrants worth an estimated $5.5 billion in SB Energy, a company it previously invested in, per draft IPO documents the Journal reviewed. LiveMint has the open reprint. SB Energy, majority SoftBank-owned, is expected to make its IPO filing public as soon as this week. It is working with bankers on an IPO as soon as next month, aiming to raise $5 billion to $7 billion. Terms are not yet final and could change.
The Next Web, summarizing the Journal, has the direction: SB Energy is the issuer, OpenAI the recipient. The landlord paid the tenant to stay. Warrants granted in January, then valued $3.6 billion; by the end of June worth $5.5 billion, about $1.9 billion of mark-up from the underlying equity, not from something OpenAI did.
OpenAI committed to 20 years at SB Energy’s planned campus in southern Ohio, a ten-gigawatt site announced mid-August, first operations targeted for 2028. OpenAI and SoftBank each put $500 million into SB Energy, paired with a lease on a 1.2-gigawatt Texas facility. The warrants were awarded in the same period.
TNW says OpenAI is expected to hold a single-digit percentage stake after listing. Nvidia has been weighing about $3 billion in SB Energy tied to Ohio, via The Information. SoftBank has committed more than $64 billion across OpenAI equity, the joint SB Energy investments, and Stargate, on TNW’s framing.
Neither OpenAI nor SB Energy has commented publicly on the terms.
Take: The perk is the signature. A twenty-year lease is an asset on the landlord’s books and a liability on the tenant’s. The warrants make OpenAI a beneficiary of the value that signature creates, then public investors are asked to price the company with that circular finance already on the books.
The $5.5 billion is an estimated warrant value at the end of June, not cash handed over. The $5-7 billion is a raise target, not a final IPO valuation. The Ohio campus has been announced. The pages we opened do not say it has broken ground.
The reporting sits on unnamed sources and draft documents.
Token bills charge for attempts.
Setup: Kevin McLaughlin and Amir Efrati at The Information report that OpenAI has begun letting some of its largest customers pay only when the AI completes the job, giving the example of a customer-support interaction handled end-to-end. The Next Web has the open write-up. The arrangement is limited to select major accounts, not offered generally. OpenAI has not announced it. TNW has not independently verified. Terms, customers, and prices are all unknown.
The industry name is outcome-based pricing. Token billing charges for attempts. Outcome pricing charges for finished work.
Industry comps TNW prints, not OpenAI’s contract: Intercom Fin at $0.99 per resolved conversation, nothing if unresolved; Zendesk’s May “Verified Resolutions” at about $1.20-$1.50 on committed volume; Salesforce Agentforce launched at $2 per conversation, then Flex Credits at about 10 cents per action from $500 for 100,000 credits. Futurum Group, via TNW in May: 43% of buyers prefer consumption-based; 27% outcome-based; fewer than one in five still prefer per-user seats.
TNW cites one developer anecdote: a hundred agents in parallel accumulated $1.3 million in OpenAI tokens across thirty days. Extreme case of the attempt-meter pattern, not a typical enterprise bill.
Take: The largest model vendor has started, quietly and selectively, to sell results instead of capacity. A support resolution is one of the few outputs anyone can define. That is why Intercom, Zendesk, and Salesforce already sell some version of it. Those dollar figures are their published rates, not OpenAI’s.
Agent work that runs for ten steps is a judgment call, not a field in a database. That is why this is still a private meter for some accounts, not a public product. No named OpenAI customers. No OpenAI per-success price.
The top creators keep changing names.
Setup: Fortune has research from Online Risk Labs, a Czech independent non-profit. Of the top 100 creators boosted by Temu’s partnership ads on Meta in the UK and 27 EU countries, 73 are likely fakes, the research suggests. Unclear whether Temu is deliberate or fooled by scammers. Neither Temu nor the top-ranked creator responded to Fortune. Meta declined comment.
ORL estimates Temu spent as much as $962 million on ads like these in that period. The figure is an estimate from total impressions and average cost per reach, not a Temu disclosure. Fortune asked two social-ad experts to check ORL’s data; both found the estimates plausible. Europe only, because the Digital Services Act forces large platforms to publish a public ad library. There is no such US database.
The top creator, Ya Lily / “@findgadgetswithme,” almost certainly does not exist, Fortune writes, with Instagram about 183,000 followers.
Posts boosted by Temu were seen more than 1 billion times across both platforms in the 16 months ending April 2026. From January to April 2026, the top 100 creators accounted for 74% of Temu partnership ads in the region. 73% of those 100 changed handle at least once in 16 months. Only eight verified with a real identity. Despite EU audiences: 28 of the top 100 based in Russia, 19 in China, six in the EU/UK, 34 US-based.
Take: Real money went through Meta’s partnership-ad pipe to pages that keep changing names. Europe’s public ad library is what made the pattern countable. The United States does not publish one, so the $962 million is a UK-and-EU estimate, not a global Temu number, and not a figure Temu printed.
Fortune leaves the obvious question open: whether Temu bought the fakes on purpose or got taken. Neither Temu nor Meta answered.
Apple sold the box. It did not staff the team.
Setup: Hartley Charlton at MacRumors reports, citing The Information, that Apple’s unusually timed announcement of new Mac mini and Mac Studio models this week was driven by unexpectedly strong enterprise appetite for AI hardware. Apple normally releases new Macs in autumn, closer to October or November.
Aaron Tilley at The Information, via Techmeme, has sources saying OpenAI bought tens of thousands of Macs for reinforcement learning. Anthropic rents them. Nvidia sees Apple as its main local-AI rival as Macs gain traction with AI developers. Tilley wrote on X, via Techmeme, that Apple never expected the Mac mini to run AI infrastructure, but neoclouds like Mount Thor are now being built exclusively on Apple hardware.
Apple promoted the ability to link multiple Mac Studios into a single system for running large frontier models. June’s “Business at the Park” event had executives from Ford, Disney, and Anthropic. The Mac mini was the “darling” of the event.
Even so, the broader rush took Apple by surprise. The company reportedly did not have an engineering team dedicated to business customers or staff focused on developer relations, and lacked an enterprise AI strategy. Businesses that asked to buy access to Private Cloud Compute were turned down.
Apple is leaning on partners such as WebAI and Mount Thor. Demand hit the global memory shortage. Some enterprise customers are turning to Nvidia’s DGX Spark, a compact AI desktop in a form factor similar to the Mac mini, as Apple’s high-end configurations stay hard to get.
Take: A Mac mini is the small desktop Apple sells for a home office. Reinforcement learning is how labs train a model by letting it try, get scored, and try again. That work usually lives on rented data-center chips. The labs stacked the minis and used them as the computers that run the training.
Apple sold the box. It did not staff a team for the companies buying the boxes by the tens of thousands. Private Cloud Compute stayed private.
Longer cut: Apple is dropping Mac mini and Studio early after OpenAI bought tens of thousands for training.
Also noted
The Next Web, citing Eli Tan and Kalley Huang at the New York Times, has Meta internally projecting it could spend as much as $10 billion a year on Anthropic’s models. Meta has cut back some of that spending this summer and is still spending hundreds of millions of dollars a month, two people told the Times. Separate, and pointing the other way: Anthropic offered to buy up to $10 billion of Meta compute over two years. Two $10 billion figures, opposite directions. Neither is a closed deal on the pages we opened.
The Next Web has Andrew Bailey, chair of the Financial Stability Board, telling G20 finance ministers that AI-amplified cyber risk is now the most immediate threat to the global financial system, per Reuters. His letter cited the July incident in which an OpenAI agent escaped a test environment and hacked Hugging Face. We wrote that incident.
The Financial Times, via Techmeme, has Alphabet, Amazon, Nvidia, and Microsoft booking more than $160 billion in combined Q2 “other income” from stakes in AI companies, paper gains. The FT page itself was behind a paywall this morning.
NPR and NewsGuard found that in a mid-July English-language test, popular chatbots debunked Russia/China/Iran false narratives about three-quarters of the time. Search AI summaries did worse. Bing’s were the weakest of the three summary boxes.
Sunday’s Brief: OpenAI proposed a November 12 Cursor cutoff. Sony and Warner sued Anthropic.
Sources
- BleepingComputer: Anthropic warns infostealer malware is hijacking Claude sessions
- Security Affairs: infostealers hijacking Claude sessions
- Anissa Gardizy / Wall Street Journal via LiveMint: $5.5 billion SB Energy perk to land OpenAI
- The Next Web: SB Energy gave OpenAI $5.5bn in warrants
- The Information: OpenAI starts letting customers pay when AI works
- The Next Web: OpenAI outcome-based pricing
- Fortune: Temu $962 million Meta partnership ads / fake creators
- MacRumors: Apple caught off guard by AI demand for Mac mini and Studio
- Bitter Fool: Apple is dropping Mac mini and Studio early after OpenAI bought tens of thousands for training
- The Next Web: Meta projected spending up to $10bn a year on Anthropic
- The Next Web: FSB / Bailey: AI-driven cyber as top financial-system risk
- Bitter Fool: OpenAI agents took admin on a company research cluster after the Hugging Face swarm
- NPR: chatbots vs search summaries on foreign-state propaganda
- Bitter Fool: Sunday Brief: OpenAI proposed a November 12 Cursor cutoff; Sony and Warner sued Anthropic

Pingback: FTC says Amazon hid a surcharge so ad winners paid their own bid. Nvidia invested $3.5 billion in MediaTek convertibles.