deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Infostealer malware drains Claude subscriber tokens, Anthropic warns affected users

Attackers are using infostealer malware to steal Claude login sessions and quietly burn through paid subscribers' token quotas, with Anthropic warning some users and issuing refunds.

Infostealer malware drains Claude subscriber tokens, Anthropic warns affected users

How the theft surfaced

Grant De Swardt, an independent AI consultant based in East Sussex in the U.K., first noticed something wrong on August 4. As TechCrunch reports, his Claude Max 20x plan was consuming tokens on a day he had not worked. When he disconnected everything attached to the account and again did nothing, usage kept climbing anyway — in one controlled window it moved from 45% to 55% of his quota with scheduled tasks paused or finished, cloud execution disabled and no active local Claude Code session.

He asked Anthropic for an itemized breakdown of what was consuming the quota. According to TechCrunch, the company did not provide one, but it agreed the activity looked wrong. It suspended the paid account, invalidated his sessions and server-side Claude Code tokens, and refunded £44.49 of the remaining time on his $200-per-month subscription.

The suspension disrupted his livelihood. De Swardt builds AI agents for small and mid-sized businesses, and also runs his own administration, coding and website work through the platform, he told TechCrunch.

What Anthropic found

Anthropic's investigation, as described to TechCrunch, traced the problem to a compromised Claude session key that was used to mint unauthorized Claude Code OAuth tokens. The account appeared to have been used by an outside service running activity for other people, though the company reportedly could not establish how that access was obtained. It told De Swardt the evidence fit either his credentials or session data being taken without his knowledge, or the account having been linked to an external service.

A wider pattern

De Swardt's case was not isolated. After posting about it on Reddit, he found other users describing similar experiences, TechCrunch reports. One claimed their account was upgraded without consent, their credit card was charged, and usage jumped from 0% to 100% without any activity on their part. Another saw usage rise from 0 to 49% in twelve minutes after only a couple of prompts and a web search. A third user's account hit its maximum tokens three days in a row while unused, prompting a GitHub report that drew further accounts of the same behaviour.

Two of those users shared emails from Anthropic, seen by TechCrunch, that explain the mechanics: attackers were using widely available infostealer malware to grab Claude login sessions from victims' machines, then spending down their usage from those stolen sessions. Infostealers harvest saved passwords and session data from infected computers, and Anthropic told affected users the malware did not come from using Claude itself — such infections typically arrive through infected software downloads or malicious ads. In those cases the company signed users out, invalidated existing authorizations, issued some refunds and warned them to check their machines for malware.

De Swardt, by contrast, says he never received such an email and found no evidence his computer was compromised, leaving him with no way to determine how the attackers got in.

Falling out with the platform

His account was restored after roughly two weeks, but the slow support process and the absence of itemized usage data soured him on the service. He cancelled the subscription and moved to Cursor, telling TechCrunch that alternative models perform about as well at lower cost. He also argued that Anthropic still offers no way for users to see what is drawing down their tokens, leaving subscribers with no practical means of protecting themselves.

TechCrunch says Anthropic declined to comment when asked how users can identify misuse of their accounts.

Why it matters

The incident exposes a gap between how AI subscriptions meter usage and how they report it. Subscribers can see a quota, but not what is consuming it, which allowed a stolen session to quietly drain a paid allowance for an unknown period. Session theft is also a softer target than password compromise: a hijacked session remains useful until explicitly revoked, which is why Anthropic's response — signing users out and invalidating authorizations — is the decisive remediation step. Until providers offer per-session or per-application usage breakdowns, account holders' best defences are conventional malware hygiene and periodically revoking active sessions, assuming they notice the drain at all. For professionals whose businesses run through these accounts, the episode is also a reminder that a security incident on one platform can halt their operations for weeks.

  • #anthropic
  • #claude
  • #security
  • #malware
  • #session-hijacking

Related posts