{"id":679258,"date":"2026-09-08T22:05:29","date_gmt":"2026-09-08T22:05:29","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/679258\/"},"modified":"2026-09-08T22:05:29","modified_gmt":"2026-09-08T22:05:29","slug":"hackers-are-stealing-claude-tokens-from-subscribers","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/679258\/","title":{"rendered":"Hackers are stealing Claude tokens from subscribers"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">On August 4, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed something strange going on with his Claude Max 20x account. He hadn\u2019t been working that day, yet his token usage was climbing.<\/p>\n<p class=\"wp-block-paragraph\">The next day, he disabled everything he had attached to Claude and did not work with it. Token consumption again increased. \u201cIn the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch\/cloud execution was disabled, and there was no corresponding active local Claude Code task,\u201d de Swardt told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">What was eating up his token allowance? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn\u2019t provide one, but it agreed something was off. It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued him a partial refund of \u00a344.49\u00a0for the remaining time on his $200-per-month subscription.<\/p>\n<p class=\"wp-block-paragraph\">The suspension wreaked havok on his business, he told TechCrunch. His job is to help small and mid-size businesses set up agents \u2014 a sort of forward-deployed engineer for hire \u2014 for tasks like automatically loading purchase-order data from emails into the accounting software.<\/p>\n<p class=\"wp-block-paragraph\">As a sole proprietor, he relies on agents throughout his whole business, too: daily admin tasks, website design, coding. \u201cLike everything is just running through AI these days,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">After investigating, Anthropic told de Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told him the account \u201cappeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access,\u201d he told TechCrunch. \u201cThey say the evidence is consistent either with credentials\/session data being taken without my knowledge, or with the account having been connected to an outside service.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In other words, a hacker was able to obtain access to de Swardt\u2019s account and was covertly siphoning off his tokens. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could have gone on for months undetected. <\/p>\n<p class=\"wp-block-paragraph\">He posted his <a href=\"https:\/\/www.reddit.com\/r\/ClaudeAI\/comments\/1vf6i4y\/max_20x_usage_went_from_0_to_100_in_half_an_hour\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">experience on Reddit<\/a> and after 80 comments, he discovered he was not alone. One person claimed that their account \u201cwas auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.\u201d Another saw usage go from 0 to 49% in 12 mins, when all they had used it for was a couple of prompts and a web search.<\/p>\n<p class=\"wp-block-paragraph\">One Claude user said their account burned through its max tokens every day for three days without them using it at all; this person then created <a href=\"https:\/\/github.com\/anthropics\/claude-code\/issues\/82506\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a GitHub report<\/a> about it. Like with the Reddit post, others users shared similar experiences there, too.<\/p>\n<p class=\"wp-block-paragraph\">Two of them posted emails from Anthropic where the company had \u2014 to its credit \u2014 identified and warned them that their tokens were being stolen.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people\u2019s computers, then using those login sessions to access Claude accounts and consume their usage,\u201d the email read. Infostealers are a type of malware that installs itself on a user\u2019s computer and steals saved passwords, session data, and login-credentials.<\/p>\n<p class=\"wp-block-paragraph\">When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds, and warned them that they may have malware.<\/p>\n<p class=\"wp-block-paragraph\">The company also said the malware didn\u2019t come from using Claude itself. Such malware can be picked up from many sources online, from downloading infected software to clicking on infected ads.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic did not send de Swardt one of those emails. He insists he found no evidence that his computer was compromised and says he still has no way of determining how hackers gained access.<\/p>\n<p class=\"wp-block-paragraph\">de Swardt\u2019s Claude account was reinstated after about two weeks. But the difficulty of getting speedy help for the matter, plus the lack of an itemized usage, soured him on Claude. He cancelled his subscription in favor of Cursor and its ability to use multiple models, including more affordable open-source options. <\/p>\n<p class=\"wp-block-paragraph\">In his experience, these other models work as well as Claude. \u201cIt\u2019s not that much different or better,\u201d he said, adding that he can\u2019t see going back \u201cwithout [Anthropic] actually having resolved the issue in any way.\u201d <\/p>\n<p class=\"wp-block-paragraph\">He says Anthropic still lacks tools that allows users to see what\u2019s consuming their tokens. \u201cI don\u2019t think there\u2019s any way that these people can protect themselves.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When asked for information on how users can identify misuse, Anthropic declined to comment. <\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"On August 4, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed something strange going&hellip;\n","protected":false},"author":2,"featured_media":679259,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[261],"tags":[291,6006,289,290,18,19263,19,17,82],"class_list":["post-679258","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-anthropic","tag-artificial-intelligence","tag-artificialintelligence","tag-eire","tag-hackers","tag-ie","tag-ireland","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/117237692699533957","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/679258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=679258"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/679258\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/679259"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=679258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=679258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=679258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}