Hackers Are Stealing Claude Tokens From Subscribers

Claude token theft has emerged as a growing concern among subscribers, after multiple users reported their token usage climbing dramatically without any explanation, despite not actively using the service.

On August 4, Grant De Swardt, an independent AI consultant based in East Sussex, UK, noticed something strange happening with his Claude Max 20x account. He hadn’t been working that day, yet his token usage kept rising. The following day, he disabled everything connected to Claude and avoided using it entirely, yet token consumption increased again regardless. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt told TechCrunch.

One Consultant’s Costly Ordeal

Unable to identify what was consuming his token allowance, De Swardt contacted Anthropic and requested an itemized usage breakdown. While the company didn’t provide that detailed list, it did acknowledge something was wrong, suspending his paid account, invalidating all active sessions and server-side Claude Code tokens, and issuing a partial refund of £44.49 for the remaining time on his $200-per-month subscription.

The suspension significantly disrupted his business, he told TechCrunch. De Swardt works helping small and mid-size businesses set up AI agents for tasks like automatically loading purchase-order data into accounting software. As a sole proprietor, he relies heavily on AI agents throughout his own business as well, covering daily administrative tasks, website design, and coding. “Like everything is just running through AI these days,” he said.

What Anthropic Found

After investigating, Anthropic told De Swardt it had identified the underlying cause: a compromised Claude session key had been used to generate unauthorized Claude Code OAuth tokens. According to De Swardt, the company explained his account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access.” He said Anthropic indicated the evidence was consistent either with credentials or session data being taken without his knowledge, or with his account having been connected to an outside service without his awareness.

In effect, a hacker had gained access to his account and was quietly siphoning off his token allowance. Because Anthropic’s account support system tracks total usage rather than itemized usage, even when specifically requested, this type of Claude token theft could potentially continue undetected for months at a time.

Not an Isolated Incident

After sharing his experience with Claude token theft on Reddit, De Swardt discovered he wasn’t alone. The post drew roughly 80 comments, with one user claiming their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another described watching usage jump from 0 to 49% within just 12 minutes, despite having only run a couple of prompts and a web search.

One affected user reported their account burning through maximum tokens every day for three consecutive days without any active use, prompting them to file a report on GitHub. As with the Reddit thread, other users soon shared similar experiences in response.

Two users specifically posted emails they’d received from Anthropic, in which the company had proactively identified and warned them that their tokens were being stolen. “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” one such email read. Infostealer malware typically installs itself on a victim’s computer and steals saved passwords, session data, and login credentials.

When Anthropic detected this kind of suspicious activity, it responded by signing affected users out, invalidating existing authorizations, issuing some refunds, and warning users that their devices may be infected with malware. The company also clarified that the malware itself didn’t originate from using Claude, noting it can be picked up from many common sources online, including infected software downloads or malicious ads.

An Unresolved Case and a Lost Customer

Notably, in this specific case of Claude token theft, Anthropic did not send De Swardt one of the proactive warning emails other affected users received. He maintains he found no evidence his own computer had been compromised and says he still has no way of determining exactly how the hackers gained access to his account in the first place.

De Swardt’s Claude account was eventually reinstated after roughly two weeks. However, the difficulty of getting timely support, combined with the lack of itemized usage data, ultimately soured him on the platform entirely. He canceled his subscription in favor of Cursor, drawn specifically to its ability to work across multiple AI models, including more affordable open-source options.

In his experience, these alternative models perform comparably well. “It’s not that much different or better,” he said, adding that he doesn’t see himself returning to Claude “without [Anthropic] actually having resolved the issue in any way.”

He remains critical of Anthropic’s current tools for tracking token consumption, arguing users currently have no reliable way to identify what’s actually consuming their allowance. “I don’t think there’s any way that these people can protect themselves,” he said, highlighting an ongoing gap in Claude token theft prevention that leaves subscribers vulnerable to similar incidents going forward.

AI News

Leave a Reply

Your email address will not be published. Required fields are marked *