Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Hackers steal Claude tokens from subscribers, Anthropic warns

Anthropic has warned users that hackers are using infostealer malware to steal Claude login sessions and consume their token allowances. One UK consultant had his account suspended after unauthorised token use was detected.

  • Anthropic warned users that a bad actor is using infostealer malware to steal Claude login sessions and consume usage.
  • Independent AI consultant Grant de Swardt in East Sussex, UK, had his Claude Max 20x account compromised and received a partial refund of £44.49.
  • Anthropic declined to comment on how users can identify misuse.

Anthropic has warned Claude users that hackers are using infostealer malware to steal login sessions and consume their token allowances. The company said it became aware of a bad actor using common infostealer malware to steal Claude login sessions from people's computers, then using those sessions to access accounts and consume usage.

One affected user, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed his Claude Max 20x account was consuming tokens on August 4 even though he was not working. After he disabled everything attached to Claude, token consumption still increased. Anthropic suspended his account, invalidated his sessions and tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription.

Anthropic told de Swardt that a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company said the account appeared to have been used by an unauthorized-looking third-party service, but it could not determine how access was obtained. De Swardt said he found no evidence his computer was compromised.

Other users reported similar issues on Reddit and GitHub, including accounts being auto-upgraded without consent and usage rising sharply without activity. Anthropic said the malware did not come from using Claude itself, and it has signed out affected users, invalidated authorizations, and issued some refunds.

Why this matters: The incident highlights a security risk for Claude subscribers, as token theft can go undetected due to a lack of itemized usage tracking.

What this means for you: Claude subscribers should be aware that their accounts could be accessed without their knowledge, and that Anthropic does not provide itemized usage details to help detect such misuse.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.