Business

Hackers Steal Claude Tokens From Anthropic Customers

Hackers are using infostealer malware to hijack Anthropic Claude accounts and drain subscribers' token allowances, exposing security gaps in how AI platforms track and report usage.

TechCrunch AI4 days agoBusiness
Image: TechCrunch AI

Anthropic customers are reporting that hackers are hijacking their Claude accounts to steal valuable API tokens. The issue came to light after Grant De Swardt, an AI consultant based in East Sussex, U.K., noticed his Claude Max 20x account consuming tokens while he was offline. His usage jumped from 45% to 55% during a controlled period of inactivity. Anthropic subsequently suspended his $200-per-month subscription, invalidated his server-side Claude Code tokens, and issued a partial refund of £44.49.

Anthropic later informed De Swardt that a compromised session key had been used to mint unauthorized Claude Code OAuth tokens. While De Swardt found no malware on his system, other affected users received emails from Anthropic warning them that bad actors are deploying common infostealer malware to harvest Claude login sessions. On online forums like Reddit and GitHub, multiple subscribers reported similar anomalies, including one user whose account usage spiked from 0% to 100% after an unauthorized automatic upgrade, and another who saw usage jump to 49% in just 12 minutes.

For AI practitioners and developers, this security threat poses a significant operational risk. De Swardt, who builds automated agents for small businesses, experienced severe business disruption during the two weeks his account was suspended. Because Anthropic does not provide itemized usage logs, subscribers have no native way to monitor which specific applications or sessions are burning through their token allocations.

Frustrated by the lack of transparency and the slow response times, some developers are migrating away from Anthropic's ecosystem. De Swardt ultimately canceled his subscription to switch to Cursor, an alternative that supports multiple models, including cheaper open-source options. Anthropic has declined to comment on how users can protect themselves or identify unauthorized token consumption.

This is our own summary of reporting by TechCrunch AI

More in Business