Skip to content

Hackers target Claude subscribers to steal access tokens

A hacker surreptitiously depleted an AI consultant’s Claude Max 20x subscription by Anthropic, exposing an escalating issue on the platform: attackers are gaining unauthorized access and burning through paid tokens.

Recently, Anthropic determined that infostealer malware was a major cause behind the most recent wave of account breaches. Despite this, customers are increasingly expressing concerns about their limited ability to identify or stop such covert intrusions.

Claude subscription exploited, causing operations to halt

On August 4, independent AI consultant Grant De Swardt from East Sussex, U.K., discovered that his Claude Max 20x account had recorded a surge in usage, though he had not logged any work that day. Alarmed, he proceeded to audit his connected integrations, disable any linked services, and pause automated routines—yet, his token consumption inexplicably continued to increase with no involvement on his part.

Unable to trace the source, De Swardt requested a comprehensive usage report from Anthropic. While the company couldn’t provide such detailed activity logs, they did verify irregular use, suspended his subscription, revoked all existing credentials and sessions, and refunded him £44.49 for the unused segment of his $200-per-month plan.

This sudden lockout had major implications for De Swardt’s consultancy, where AI agents are fundamental for automating purchase order entries, daily admin tasks, site management, and coding work. De Swardt explained that losing access so abruptly caused serious disruption, as he is dependent on these AI tools for ongoing business activities.

Recurring breaches and echoed complaints from users

During their inquiry, Anthropic learned that someone had used a hijacked session key from De Swardt’s account to produce unapproved Claude Code OAuth tokens. The company notified him about what they described as “an unauthorized-looking third-party service” abusing his account, attributing the incident to either a compromise of his credentials/session information or accidental authorization of a rogue service. Even after the investigation, Anthropic was unable to specify the exact method used to infiltrate his account.

De Swardt recounted his ordeal in a Reddit post, which drew over 80 further comments from others facing the same issue. One user noted their subscription was upgraded—and their payment processed—without their approval, with their usage maxing out despite no activity. Another reported a jump from 0% to 49% usage in only 12 minutes. Additional reports surfaced on GitHub, such as this account of inexplicable daily token drain, with more users corroborating similar incidents in replies.

Some users shared correspondence from Anthropic in which the company admitted they had proactively detected the suspicious activity, alerting users to the fact that account takeovers were performed via session data compromised by infostealer malware. As those emails explained: “A bad actor is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.”

To handle the breaches, Anthropic logged users out, revoked access, issued reimbursements, and alerted affected customers to potential malware infections on their machines. Anthropic clarified that using Claude itself does not expose users to the malware—rather, infections typically originate from downloading malicious software or visiting harmful sites elsewhere on the internet.

In De Swardt’s instance, he did not receive any warning or notification from Anthropic. He maintains that no malware was detected on his computer and remains unable to discover how his login details were compromised, noting that Anthropic does not provide the necessary tools to scrutinize token misuse on his account.

Inadequate transparency frustrates affected customers

De Swardt regained access to his account two weeks following the breach. Frustrated by what he saw as slow and incomplete assistance—and by the continued lack of granular usage data—he decided to terminate his Claude subscription and migrate to Cursor. This alternative platform gives him access to multiple AI models, including open source varieties that, he notes, do not differ significantly from Claude in terms of performance.

He emphasized he would not consider returning unless Anthropic fully addressed the issue. Greater transparency and detailed activity breakdowns are essential, De Swardt argued, because users are unable to guard themselves against unauthorized activity without these tools. When asked whether such features would be made available, Anthropic declined to comment.

This situation highlights persistent difficulties AI platforms face in providing a balance between user accessibility and robust security, while exposing a notable desire among customers for clearer oversight and better management of their own account activity.