Stolen credentials let attackers drain Claude subscriber accounts
An independent AI consultant based in East Sussex noticed unexplained token usage draining his Claude Max subscription in early August, despite having disabled all his automated tasks and integrations. Anthropic later confirmed a compromised session key had been used to generate unauthorised Claude Code OAuth tokens, effectively letting an unknown third party consume his usage allowance without his knowledge. The case, and similar reports from other users, points to a wider pattern of credential theft affecting Anthropic's subscriber base, raising concerns about account security and the adequacy of usage monitoring for paid AI services.
Anthropic suspended the consultant's account, invalidated his sessions and tokens, and issued a partial refund of £44.49 against his $200 monthly subscription, though the disruption still hit his business, which relies heavily on Claude-powered agents. After he shared his experience on Reddit, dozens of other users reported similar incidents, including accounts auto-upgraded without consent, sudden spikes in usage within minutes, and daily token limits being exhausted overnight. Anthropic has acknowledged the issue internally, telling affected users in emails that a "bad actor" is deploying common infostealer malware to steal Claude login sessions from victims' computers and use them to consume their account usage, after which it signs out affected users and invalidates their credentials.
- Hackers using infostealer malware are hijacking Claude accounts to steal token usage.
- A UK consultant's Max subscription was drained via a stolen session key.
- Anthropic confirms the issue, refunds some users, and revokes compromised sessions.
New here? Start with this
Anthropic's Claude is an AI system used by consumers, developers and businesses, often through paid subscriptions like Claude Max that grant a set amount of "usage" (measured in tokens, the units AI systems process text in) each month. Access to these accounts relies on login credentials and session keys, which act like digital passes proving a user is who they say they are.
This story concerns reports that criminals have been stealing these login credentials, typically using "infostealer" malware that lifts saved session data from a victim's computer, and then using them to access other people's Claude accounts without permission. Because the stolen access looks legitimate to Anthropic's systems, the attackers can quietly consume a victim's monthly usage allowance, sometimes upgrading accounts or exhausting daily limits within minutes.
The issue matters because it affects paying customers, some of whom run businesses or automated tools that depend on Claude, and raises broader questions about how well AI companies secure accounts and detect unusual activity before real damage is done.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Advocates for greater platform responsibility argue that Anthropic, as the operator of a paid subscription service, has both the capability and the obligation to detect anomalous usage patterns in real time, such as sudden spikes or overnight exhaustion of token limits, before a customer's allowance is drained. They contend that a £44.49 refund against a $200 monthly bill is inadequate given the disruption caused to paying customers' businesses, and that a company profiting from usage-based billing should bear more of the cost when its monitoring systems fail to flag obviously abnormal activity, including unauthorised account upgrades that a legitimate user would be unlikely to trigger themselves.
The case against
Others reasonably point out that the root cause here is malware installed on individual users' own devices, which stole session credentials outside Anthropic's systems entirely, meaning the company was not the party whose security was breached. From this view, Anthropic acted responsibly and promptly once notified, suspending compromised accounts, invalidating tokens, and issuing partial refunds, and expecting a provider to fully underwrite losses caused by a customer's own compromised endpoint risks setting an unsustainable precedent. They would argue the more proportionate response is for users to strengthen personal device security, such as antivirus protection and credential hygiene, while Anthropic continues improving detection as a supplementary safeguard rather than a primary guarantee.
Read the full article at the source →
Originally published by TechCrunch as “Hackers are stealing Claude tokens from subscribers”.