Hackers Steal Claude Subscriber Tokens via Session Keys, Consultant Finds

Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed on August 4 that his Claude Max 20x account was consuming tokens while he was not working. The next day he disabled everything attached to Claude and did not work with it, but token consumption again increased. In his words: “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task.” He asked Anthropic for an itemized usage list; instead, Anthropic agreed something was off, suspended his paid account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription.

The suspension disrupted his business: de Swardt is a sole proprietor who helps small and mid-size businesses set up agents, and he also relies on agents for his own daily admin, website design, and coding. After investigating, Anthropic reported that a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. The account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people,” but Anthropic could not determine how it obtained access. The evidence was consistent either with credentials/session data being taken without his knowledge or with the account having been connected to an outside service. Since account support tracks total usage rather than itemized usage, even upon request, this kind of theft could have gone on for months undetected.

After de Swardt posted on Reddit, other Claude users reported similar problems. One said their account was auto-upgraded without consent, their credit card was charged, and usage shot from 0% to 100% without them touching it. Another saw usage go from 0% to 49% in 12 minutes after only a couple of prompts and a web search. Another burned through their max tokens every day for three days without using the account and filed a GitHub report. Two users shared emails from Anthropic in which the company warned them: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” Anthropic signed affected users out, invalidated existing authorizations, issued some refunds, and warned them they may have malware, adding that the malware did not come from using Claude itself.

Anthropic did not send de Swardt one of those emails. He said he found no evidence his computer was compromised and still has no way to determine how hackers gained access. His account was reinstated after about two weeks, but the lack of speedy help and the lack of itemized usage soured him on Claude. He cancelled his subscription in favor of Cursor, which lets him use multiple models including more affordable open-source options; in his experience, these models work as well as Claude. “It’s not that much different or better,” he said, adding that he cannot see going back “without [Anthropic] actually having resolved the issue in any way.” He believes Anthropic still lacks tools for users to see what consumes their tokens: “I don’t think there’s any way that these people can protect themselves.” Anthropic declined to comment on how users can identify misuse.

Hackers are stealing Claude tokens from subscribers | TechCrunch

View Original