Prompt and Model
Regulation

Hackers steal Claude tokens via stolen

Anthropic users report hackers using stolen session keys to siphon paid Claude tokens, with the company identifying infostealer malware as a common cause

Anthropic users report hackers using stolen session keys to siphon paid Claude tokens, with the company identifying...

Grant De Swardt, an independent AI consultant in the U.K., discovered his Claude Max 20x account was consuming tokens while he was not working on August 4. His token usage climbed from 45% to 55% in a controlled interval despite all his connected services being disabled.

Anthropic suspended his $200-per-month account, issued a partial refund of £44.49, and invalidated his sessions after an investigation. The company told him a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens, indicating a hacker was covertly using his account.

Widespread Token Theft Reports

De Swardt posted his experience on Reddit, prompting other users to share similar incidents. One user claimed their account was auto-upgraded and their credit card charged without consent, with token usage shooting from 0% to 100% automatically. Another reported usage jumping from 0 to 49% in just 12 minutes after minimal personal use.

A separate GitHub report detailed an account that burned through its maximum token allowance daily for three days without the owner's activity. In response to these reports, Anthropic emailed some users to warn them of the theft.

Anthropic Identifies Malware Vector

The company's warning email stated a bad actor was using common infostealer malware to steal Claude login sessions from people's computers. This malware installs itself to steal saved passwords, session data, and login credentials. Anthropic emphasized the malware did not originate from using Claude itself but could be picked up from various online sources like infected software or ads.

Upon detecting suspicious activity, Anthropic's response included signing users out, invalidating existing authorizations, and issuing some refunds. However, De Swardt did not receive such an email and insists he found no evidence his computer was compromised.

Lack of Transparency and User Tools

A key issue for De Swardt was the inability to obtain an itemized list of his token usage from Anthropic, even upon request. Account support only tracks total usage, which he argues allows this kind of theft to continue undetected for months. This lack of transparency, combined with the difficulty of getting speedy help, led him to cancel his subscription.

He has switched to using Cursor, which offers the ability to use multiple models, including more affordable open-source options. He states these other models work as well as Claude for his needs, seeing little difference in performance.

De Swardt's account was reinstated after about two weeks, but he remains critical. He says Anthropic still lacks tools that allow users to see what is consuming their tokens, leaving users unable to protect themselves effectively. When asked for information on how users can identify misuse, Anthropic declined to comment.

Related coverage

More from Regulation