Home
About Us
Read the Blog
Close-up of a computer screen showing an 'Authentication Failed' error message
NewsAnthropicUpdated

Hackers Are Stealing Claude Tokens From Subscribers

Hackers are using infostealer malware to hijack Claude login sessions and drain paid subscribers' token usage, and Anthropic still can't tell most users what's consuming their tokens.

Techmash

Techmash

Hackers are draining paid Claude subscribers' Claude tokens without their knowledge, using malware that steals active login sessions instead of passwords. Anthropic has started warning some affected users directly, after a UK-based AI consultant watched his Claude Max 20x account burn through usage on days he never touched it. Anthropic traced his case to a stolen session key, but it still can't tell most subscribers what is consuming their tokens, or how the attacker got in.

How hackers are stealing Claude subscriber tokens

Attackers are using common infostealer malware to lift active Claude login sessions straight off victims' computers, then reusing those sessions to access accounts and burn through their token allowance. Anthropic confirmed the campaign directly to some of the people it affected.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Anthropic, in a warning email to affected users

The malware itself doesn't come from using Claude. This kind of malware typically arrives through phishing links, poisoned ads, cracked software, or a fake update prompt. Once installed, they copy saved passwords and session cookies off the infected device without the victim noticing. A session cookie keeps a browser or app logged in without asking for a password again. Stealing one lets an attacker walk straight into an account, no password or two-factor code required. Anthropic says that once it spots this kind of activity, it signs the account out, invalidates the stolen authorization, and issues a warning.

Why Anthropic can't tell users what's draining their tokens

Grant De Swardt first noticed his Claude Max 20x account burning tokens on August 4, despite doing no work that day. He's an independent AI consultant based in East Sussex, UK. The next day he disabled every tool connected to Claude, and usage still climbed, rising from 45% to 55% during what he called the clearest controlled interval, with no active local or cloud Claude Code task running.

Anthropic's investigation traced the cause to a compromised session key, one that had minted unauthorized OAuth tokens for Claude Code without his knowledge. The company suspended his account, invalidated his sessions and server-side tokens, and refunded £44.49 of his $200-a-month subscription, but it couldn't say how the hacker got in, and it never sent him one of the warning emails other affected users received.

The deeper problem, De Swardt told TechCrunch, is that Anthropic's support tracks total usage but not an itemized breakdown, even on request, so theft like this could run for months undetected. Anthropic declined to comment when asked how users can identify misuse on their own.

"I don't think there's any way that these people can protect themselves." Grant De Swardt, independent AI consultant

Signs your Claude account has been compromised

The clearest sign is token usage climbing while every Claude-connected tool is switched off, the exact pattern De Swardt tracked when his account moved from 45% to 55% usage with nothing running. Other users reported similar spikes after his post: one account was auto-upgraded to a paid tier without consent and charged a credit card automatically, another jumped from 0% to 49% usage in 12 minutes after only a couple of prompts, and a third burned its full daily token limit for three straight days, prompting its owner to file a GitHub report.

Beyond usage spikes, general infostealer warning signs include logins from unfamiliar locations or odd hours, and a single account showing activity from multiple countries at once. None of these alone proves an account is compromised, but together with an unexplained jump in token usage, they're worth acting on immediately.

How to protect your Claude account from token theft

Session-cookie theft doesn't care how strong a password is, so the defenses that matter most catch a hijacked session fast, rather than relying on passwords alone. A password manager keeps credentials out of the browser, which is harder for infostealers to raid than a browser's built-in store. Multi-factor authentication still helps, but it has a limit: MFA blocks a stolen password from being reused, not an attacker who already holds an active session cookie.

Most infections start the same ordinary ways: pirated software, cracked plugins, fake browser updates, unsolicited attachments. Avoiding those cuts off the most common route in. Anthropic doesn't itemize consumption, so checking the usage dashboard after periods of inactivity is currently the closest thing to an early warning subscribers have. Logging out of every active session after a suspicious spike forces a stolen cookie to stop working right away. Until Anthropic builds itemized tracking, catching a spike early is still a subscriber's best defense.

Techmash

Techmash

FAQ

Frequently Asked Questions

Infostealer malware on a victim's computer steals their active Claude login session, letting an attacker access the account and consume its token allowance without needing the victim's password.

Not on its own. If the malware has already stolen an active session cookie, the attacker is using a session that's already logged in, so MFA on a fresh login attempt doesn't apply.

In at least one reported case, yes. Anthropic suspended the affected account, invalidated its sessions, and issued a partial refund, though it has not detailed a standard policy for these cases.

Watch for token usage climbing while you aren't using Claude and every connected tool is turned off, unexpected plan upgrades or charges, or usage jumping sharply within minutes of light activity.

Category

News

The latest AI news across OpenAI, Anthropic, Google and the wider industry

[ Related ]

More in News