Hackers stealing Claude AI tokens from subscribers via infostealer malware

Users report unauthorized token consumption; Anthropic warns of compromised session keys

edit
By LineZotpaper
Published
Read Time2 min
Sources2 outlets
Grant De Swardt, an independent AI consultant in East Sussex, U.K., discovered unexplained token usage on his Claude Max 20x account in early August, leading to an investigation by Anthropic that revealed a compromised session key was used to mint unauthorized tokens. The company has warned users that infostealer malware is being used to steal login sessions, and multiple subscribers have reported similar incidents.

On August 4, Grant De Swardt noticed his Claude Max 20x account's token usage was climbing even when he wasn't working. The next day, after disabling all attached tools, token consumption again increased — from 45% to 55% in one controlled interval, he told TechCrunch. De Swardt contacted Anthropic, which suspended his paid account, invalidated all sessions and server-side tokens, and issued a partial refund of £44.49.

Anthropic's investigation found that a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told De Swardt the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access."

De Swardt posted his experience on Reddit and discovered others had similar problems. One user reported their account was auto-upgraded and credit card charged without consent, with usage jumping from 0% to 100%. Another saw usage go from 0 to 49% in 12 minutes after minimal use. A GitHub issue on the Claude Code repository also collected similar reports.

Two users posted emails from Anthropic in which the company warned: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Anthropic signed affected users out, invalidated authorizations, and issued some refunds.

Because Anthropic's account support tracks total usage but not itemized usage even upon request, such theft could go undetected for months. The suspension also disrupted De Swardt's business, as he relies on agents for daily admin, website design, and coding. "Like everything is just running through AI these days," he said.

§

Analysis

Why This Matters

  • AI subscription tokens are a valuable target: attackers can resell access or use it for their own computational tasks, costing victims money and potentially violating usage policies.
  • The lack of granular, real-time usage monitoring leaves users vulnerable to prolonged theft without detection.
  • This incident highlights a broader security challenge for AI platforms that manage high-value token-based subscriptions.

Background

Infostealer malware has become a widespread threat in recent years, often used to steal saved passwords, session cookies, and login credentials from infected computers. AI subscription services like Claude treat tokens as a finite resource, making them an attractive target for attackers who can siphon usage for their own purposes. The incident follows a pattern of credential theft affecting cloud services, but token theft in AI platforms presents unique detection challenges due to opaque usage reporting.

Key Perspectives

Affected users: Face financial loss from stolen tokens and business disruption when accounts are suspended. They want itemized usage logs and proactive alerts before tokens are exhausted. Anthropic: Has responded by suspending accounts, invalidating sessions, and issuing refunds, but users remain frustrated by the lack of transparency in monitoring and the slow response to unauthorized activity. Security critics: Note that infostealer malware is a known and preventable threat. Users should avoid storing session tokens in browsers without protection and enable multi-factor authentication where available. The incident also raises questions about whether AI companies are doing enough to secure their authentication flows.

What to Watch

  • Whether Anthropic adds granular, real-time usage tracking and alerts as a standard feature.
  • If other AI subscription services (OpenAI, Google, etc.) report similar token-theft incidents.
  • Potential growth in targeted infostealer campaigns aimed at AI users as the value of tokens increases.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.