
Interesting, I killed my OpenClaw VPS servers months ago But today I got a billing alert on its separate Claude account (claudeforopenclaw@), it didn't have auto reload on but I guess at some point it got hacked and the Claude key inside OpenClaw got exposed and then they waited for months before using it on Fable 5.1 I checked all my terminals and VPS sessions and none of them use API so it's interesting Anyway I nuked the Claude account, good I kept it on its own separate one

Shows a real case of an exposed Claude API key being silently exploited months later, only caught via billing alerts on a separately scoped account, a practical argument for per-project key isolation.
Checking sign-in…
Loading comments…