
Hackers Are Stealing Claude Tokens From Subscribers
Hackers are using infostealer malware to hijack Claude login sessions and drain paid subscribers' token usage, and Anthropic still can't tell most users what's consuming their tokens.
Hackers are draining paid Claude subscribers' Claude tokens without their knowledge, using malware that steals active login sessions instead of passwords. Anthropic has started warning some affected users directly, after a UK-based AI consultant watched his Claude Max 20x account burn through usage on days he never touched it. Anthropic traced his case to a stolen session key, but it still can't tell most subscribers what is consuming their tokens, or how the attacker got in.
How hackers are stealing Claude subscriber tokens
Attackers are using common infostealer malware to lift active Claude login sessions straight off victims' computers, then reusing those sessions to access accounts and burn through their token allowance. Anthropic confirmed the campaign directly to some of the people it affected.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Anthropic, in a warning email to affected users
The malware itself doesn't come from using Claude. This kind of malware typically arrives through phishing links, poisoned ads, cracked software, or a fake update prompt. Once installed, they copy saved passwords and session cookies off the infected device without the victim noticing. A session cookie keeps a browser or app logged in without asking for a password again. Stealing one lets an attacker walk straight into an account, no password or two-factor code required. Anthropic says that once it spots this kind of activity, it signs the account out, invalidates the stolen authorization, and issues a warning.
Why Anthropic can't tell users what's draining their tokens
Grant De Swardt first noticed his Claude Max 20x account burning tokens on August 4, despite doing no work that day. He's an independent AI consultant based in East Sussex, UK. The next day he disabled every tool connected to Claude, and usage still climbed, rising from 45% to 55% during what he called the clearest controlled interval, with no active local or cloud Claude Code task running.
Anthropic's investigation traced the cause to a compromised session key, one that had minted unauthorized OAuth tokens for Claude Code without his knowledge. The company suspended his account, invalidated his sessions and server-side tokens, and refunded £44.49 of his $200-a-month subscription, but it couldn't say how the hacker got in, and it never sent him one of the warning emails other affected users received.
The deeper problem, De Swardt told TechCrunch, is that Anthropic's support tracks total usage but not an itemized breakdown, even on request, so theft like this could run for months undetected. Anthropic declined to comment when asked how users can identify misuse on their own.
"I don't think there's any way that these people can protect themselves." Grant De Swardt, independent AI consultant
Signs your Claude account has been compromised
The clearest sign is token usage climbing while every Claude-connected tool is switched off, the exact pattern De Swardt tracked when his account moved from 45% to 55% usage with nothing running. Other users reported similar spikes after his post: one account was auto-upgraded to a paid tier without consent and charged a credit card automatically, another jumped from 0% to 49% usage in 12 minutes after only a couple of prompts, and a third burned its full daily token limit for three straight days, prompting its owner to file a GitHub report.
Beyond usage spikes, general infostealer warning signs include logins from unfamiliar locations or odd hours, and a single account showing activity from multiple countries at once. None of these alone proves an account is compromised, but together with an unexplained jump in token usage, they're worth acting on immediately.
How to protect your Claude account from token theft
Session-cookie theft doesn't care how strong a password is, so the defenses that matter most catch a hijacked session fast, rather than relying on passwords alone. A password manager keeps credentials out of the browser, which is harder for infostealers to raid than a browser's built-in store. Multi-factor authentication still helps, but it has a limit: MFA blocks a stolen password from being reused, not an attacker who already holds an active session cookie.
Most infections start the same ordinary ways: pirated software, cracked plugins, fake browser updates, unsolicited attachments. Avoiding those cuts off the most common route in. Anthropic doesn't itemize consumption, so checking the usage dashboard after periods of inactivity is currently the closest thing to an early warning subscribers have. Logging out of every active session after a suspicious spike forces a stolen cookie to stop working right away. Until Anthropic builds itemized tracking, catching a spike early is still a subscriber's best defense.
FAQ
Frequently Asked Questions
[ Related ]
More in News
Claude Fable 5.1 Launches, Cuts Agentic Task Costs 45%
Anthropic's Claude Fable 5.1 and Mythos 5.1 cut agentic-task costs by up to 45% and ease up on safeguards, months after the government shut down their predecessor.
Claude Cowork Now Remembers Your Chat History
Anthropic merged the memory behind Claude chat and Claude Cowork, so Cowork tasks now start with context you already built in chat.
Anthropic's Approach to Teaching AI: Inside Claude Academy
Anthropic launched Claude Academy and explained why: the same 4D Fluency Framework it teaches new employees now shapes how it teaches the public to use AI.
Anthropic Confidentially Files for IPO, Beating OpenAI to Wall Street
Anthropic confidentially filed a draft S-1 with the SEC on June 1, 2026, days after a $65 billion raise pushed its valuation to $965 billion, edging ahead of OpenAI in the race to go public.
Why the Government Just Forced a Total Shutdown of Anthropic’s Newest AI Models
The US government halted Anthropic's Claude Fable 5 and Mythos just days after launch over major national security and autonomous exploit risks.
U.S. Government Shuts Down Anthropic Claude Fable 5 & Mythos
The U.S. government ordered Anthropic to immediately cut off global access to Claude Fable 5 and Claude Mythos 5, citing national security concerns. Anthropic complied but publicly disagreed with the decision.
Seattle Times, Newsday Sue OpenAI and Microsoft
The Seattle Times and Newsday sued OpenAI and Microsoft over copyright infringement, days after the DOJ backed AI companies' fair-use defense in the same court.
Hikers Rescued After Trusting Gemini for Trip Planning
Three hikers had to be rescued off Mount Shasta after Gemini told them to pack for an 8-hour trip that turned into a 39.5-hour ordeal. Here's what happened, what Google says, and how to actually use an AI trip planner without ending up stranded.








