Hackers steal Claude tokens from paid subscribers using infostealer malware

Hackers steal Claude tokens from paid subscribers using infostealer malware

Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed on August 4 that his Claude Max 20x account's token usage was climbing even though he had not been working that day. The next day he disabled everything connected to Claude and still watched consumption rise. In one controlled interval, usage went from 45% to 55% while he did no work, his scheduled Cowork tasks were paused or already finished, cloud-side Dispatch execution was disabled, and no local Claude Code task was active.

De Swardt asked Anthropic for an itemized breakdown of what was consuming his tokens. Anthropic could not provide one but agreed something was wrong: it suspended his paid account, invalidated all his sessions and server-side Claude Code tokens, and refunded him £44.49 for unused time on his $200-per-month subscription. Anthropic later told him it had traced the cause to a compromised Claude session key; the account appeared to have been used by an unauthorized third-party service handling activity for other people, though Anthropic could not determine how access was obtained. De Swardt says he found no evidence his own computer was compromised and still does not know how the attacker got in. His account was reinstated after about two weeks.

The disruption hit his work directly: he builds and runs agents for small and mid-size businesses, such as pulling purchase-order data from email into accounting software, and relies on Claude for his own admin tasks, coding and website design. When he described the episode on Reddit, the post drew 80 comments from other users reporting similar problems. One said their account was auto-upgraded without consent, their credit card was charged, and usage shot from 0% to 100% automatically without them touching it. Another saw usage climb from 0 to 49% in 12 minutes after only a couple of prompts and a web search. A separate Claude user reported burning through the daily token maximum for three straight days without using the product at all, and filed a GitHub report that drew more accounts of the same pattern.

Two affected users shared warning emails Anthropic had sent them. One read: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Infostealers are malware that harvest saved passwords, session data and login credentials from an infected computer. Anthropic said the malware itself was not distributed through Claude but picked up elsewhere, such as infected downloads or ads. When it spotted the suspicious activity on these accounts, Anthropic signed the users out, invalidated their existing authorizations and issued some refunds. De Swardt did not receive one of these warning emails.

The combination of the account suspension, what De Swardt described as slow support, and the lack of itemized usage tracking led him to cancel his Claude subscription in favor of Cursor, which lets him switch between multiple models, including cheaper open-source ones. He said the alternatives work about as well for his purposes: "It's not that much different or better." He added he cannot see going back to Claude "without [Anthropic] actually having resolved the issue in any way." Anthropic declined to comment when asked what tools, if any, let users identify what is consuming their tokens.

Key facts

  • De Swardt's Claude token usage rose from 45% to 55% during a controlled interval in which he did no work and had disabled Cowork, Dispatch and local Claude Code activity.
  • Anthropic suspended his account, invalidated his sessions and Claude Code tokens, refunded £44.49 of his $200-per-month subscription, and traced the incident to a compromised Claude session key; the account was reinstated after about two weeks.
  • Anthropic emailed some other affected users a warning that a bad actor is using common infostealer malware to steal Claude login sessions and consume victims' usage; De Swardt did not receive such an email.
  • Other users described accounts jumping from 0% to 100% usage after an unauthorized auto-upgrade, or from 0 to 49% in 12 minutes after light use, and one account burned through its daily token cap for three straight days.
  • Because Anthropic's account support tracks total usage but not an itemized breakdown even on request, the theft could go undetected for months; De Swardt switched to Cursor afterward.

Why it matters

Claude's paid tiers, including the $200-a-month Max 20x plan involved here, are billed on token consumption, and this story shows that consumption can be silently hijacked by someone else entirely. Because Anthropic's account support shows only a total usage figure and not an itemized log, a subscriber has no way to tell routine use from theft until the allowance runs out or Anthropic itself flags suspicious activity. That gap turns a security incident into a billing and business-continuity problem at once, as De Swardt's suspended account and paused agent work show.

Who it affects

Anyone paying for Claude access, but the exposure is sharpest for people like De Swardt who run their business on top of it: solo operators and small teams using Claude and its agents (Cowork, Dispatch, Claude Code) for client work, coding and daily admin. Multiple other Claude subscribers described nearly identical symptoms on Reddit and GitHub, and at least two received direct warning emails from Anthropic about compromised login sessions.

How to use it

There is no vendor tool from Anthropic to self-diagnose this: when TechCrunch asked what lets users identify what is consuming their tokens, Anthropic declined to comment, and De Swardt says he still has no way to determine how his account was accessed. The practical defense sits upstream of Claude, in ordinary anti-infostealer hygiene, since Anthropic says the malware is not distributed through Claude itself but picked up from infected downloads or ads elsewhere; a sudden, unexplained jump in usage or an unrequested plan upgrade is the signal to contact Anthropic support and rotate credentials immediately.

How solid is it

The account rests on a named, on-the-record source (De Swardt) with a specific, time-stamped anomaly and direct quotes from Anthropic's own explanation to him, corroborated by a Reddit thread with 80 comments, a separate GitHub report, and two other users who shared Anthropic's own warning emails describing the same infostealer pattern. Anthropic confirmed the general phenomenon and De Swardt's suspension and refund, though it declined to comment on user-facing detection tools.

Risks and caveats

The source does not give a total count of affected users, only the specific cases described. Anthropic told De Swardt it could not determine how access to his account was obtained, and he found no evidence his own computer was compromised, so his individual case is not confirmed to be an infostealer infection like the others; no name is given for the malware family used against the other victims, only that it is common infostealer malware, and the source does not say when Anthropic first became aware of the wider pattern.

“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.”

— Anthropic, in a warning email sent to affected users