Hackers Stole Claude Tokens From Subscribers Using Stolen Session Keys, Anthropic Warns

Hackers have been stealing Claude AI tokens from paying subscribers by hijacking their account sessions, Anthropic confirmed in September 2026. The company has warned affected users, signed them out, invalidated their authorizations, and issued some refunds.

The issue came to light after Grant de Swardt, an independent AI consultant based in East Sussex, UK, noticed his Claude Max 20x account — a $200-per-month subscription — was consuming tokens on August 4, 2026, despite him not working. Even after disabling connected tools and pausing scheduled tasks the following day, token usage continued to climb. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work,” de Swardt told TechCrunch.

After de Swardt contacted Anthropic, the company investigated and found that a compromised session key had been used to mint unauthorized Claude Code OAuth tokens. Anthropic told him his account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people,” though it could not determine how access was obtained. His account was suspended for about two weeks, disrupting his business operations. He received a partial refund of £44.49.

When de Swardt posted about his experience on Reddit, dozens of other users reported similar problems, including accounts being auto-upgraded without consent and token usage spiking to 100% without any user activity. A GitHub report drew additional accounts of the same issue.

In emails sent to some affected users, Anthropic identified the cause as infostealer malware — software that installs itself on a victim’s computer and steals saved passwords, session data, and login credentials. The company stated the malware did not originate from Claude itself and could be picked up from various online sources, including infected software downloads or malicious ads.

De Swardt ultimately cancelled his Claude subscription in favor of Cursor. He says Anthropic still lacks tools that let users see what is consuming their tokens, and the company declined to comment when asked how users can identify misuse. “I don’t think there’s any way that these people can protect themselves,” he said.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top