Tuesday, 8 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 9 September 2026 at 01:21

Hackers drain Claude token subscriptions while Anthropic flags infostealer malware

A U.K. AI consultant saw his paid Claude account lose tokens without any activity, and Anthropic later linked the incident to a compromised session key. Other subscribers report similar theft and outline a lack of usage controls.

Foto: TechCrunch

Grant De Swardt, an independent AI consultant from East Sussex, U.K., noticed unusual token activity on his Claude Max 20x account on August 4. Even though he was not working that day, token consumption kept rising. After he disconnected all tools from Claude and paused tasks, usage in one clearly controlled interval went from 45% to 55% while he performed no work.

De Swardt contacted Anthropic and asked for an itemized usage report, but the company did not provide one. However, it acknowledged that something was wrong: it suspended his paid account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription. The suspension disrupted his work helping small and medium businesses set up AI agents; as a sole proprietor, he also relies on such agents for daily admin tasks, website design, and coding.

After an investigation, Anthropic told De Swardt that a compromised Claude session key had been used to create unauthorized Claude Code OAuth tokens. The company said his account appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but it could not determine how that service obtained access. The evidence was consistent either with credentials or session data being taken without De Swardt's knowledge or with the account being connected to an outside service. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could have continued for months unnoticed.

De Swardt posted his experience on Reddit, and after 80 comments he realized he was not alone. One person claimed their account was auto-upgraded without consent, their credit card was charged, and usage jumped from 0% to 100% without them touching it. Another said usage rose from 0% to 49% in 12 minutes after only a few prompts and a web search. A third reported their tokens were exhausted every day for three days while they did not use Claude at all, and they filed a report on GitHub.

Two users shared emails from Anthropic in which the company warned them that a bad actor had used infostealer malware to steal their Claude login sessions. Infostealers are designed to harvest saved passwords, session data, and login credentials from infected computers. Anthropic said it had signed the affected users out, invalidated existing authorizations, issued refunds, and warned about possible malware. The company also noted that the malware did not come from using Claude itself and could be picked up from downloading infected software or clicking malicious ads.

De Swardt never received one of those warning emails. He says he found no evidence that his computer was compromised and still has no way to determine how hackers gained access. His account was restored after about two weeks, but the difficulty of getting timely help and the lack of itemized usage soured him on the platform. He canceled his Claude subscription and switched to Cursor, which supports multiple models, including more affordable open-source options. In his view, those models work just as well as Claude. He also says Anthropic still lacks tools that let users see what consumes their tokens, and he doubts users can protect themselves. Anthropic declined to comment on how people can identify misuse.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category