Claude Token Theft: Why Hackers Are Stealing Subscriptions

Matilda
7 Min Read

On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange with his Claude Max 20x account. He hadn’t been working that day, yet his Claude token usage was climbing.

The next day, he disabled everything attached to Claude and did not work with it. Token consumption again increased. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt said.

When Claude token theft happens, users typically notice unusual usage patterns. De Swardt contacted Anthropic and requested an itemized list of his token consumption. Anthropic didn’t provide one but agreed something was off. They suspended his paid account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription.

How Claude Token Theft Happens

Anthropic investigated and found the culprit: a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told De Swardt his account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access.”

According to Anthropic, “the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.” In other words, a hacker obtained access to De Swardt’s account and was covertly siphoning off his Claude tokens.

Because account support tracks total usage but not itemized usage, even upon request, this kind of Claude token theft could go on for months undetected.

The Infostealer Malware Connection

Anthropic has identified that a bad actor is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage. Infostealers are a type of malware that installs itself on a user’s computer and steals saved passwords, session data, and login credentials.

The company emphasized that the malware didn’t come from using Claude itself. Such malware can be picked up from many sources online, from downloading infected software to clicking on infected ads.

Real Stories from Affected Users

De Swardt shared his experience on a public forum and discovered he was not alone. After 80 comments, other users shared similar experiences:

  • One person claimed their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.”

  • Another saw usage go from 0 to 49% in 12 minutes, when all they had used it for was a couple of prompts and a web search.

  • One user’s account burned through its max tokens every day for three days without them using it at all. This person then created a public report about it.

Two affected users posted emails from Anthropic where the company had—to its credit—identified and warned them that their Claude tokens were being stolen. When Anthropic saw suspicious activity, it signed users out, invalidated existing authorizations, issued refunds, and warned them that they may have malware.

The Business Impact of Claude Token Theft

The suspension of De Swardt’s account wreaked havoc on his business. His job is to help small and mid-size businesses set up agents—a sort of forward-deployed engineer for hire—for tasks like automatically loading purchase-order data from emails into accounting software.

As a sole proprietor, he relies on agents throughout his whole business, including daily admin tasks, website design, and coding. “Like everything is just running through AI these days,” he said.

Why Protection Remains Difficult

De Swardt’s Claude account was reinstated after about two weeks. But the difficulty of getting speedy help, plus the lack of itemized usage, soured him on Claude. He cancelled his subscription in favor of another tool with the ability to use multiple models, including more affordable open source options.

In his experience, these other models work as well as Claude. “It’s not that much different or better,” he said, adding that he can’t see going back “without [Anthropic] actually having resolved the issue in any way.”

He says Anthropic still lacks tools that allow users to see what’s consuming their tokens. “I don’t think there’s any way that these people can protect themselves.” Anthropic declined to comment when asked for information on how users can identify misuse.

How to Protect Your Claude Account

While Anthropic has not published detailed guidance, there are steps you can take to reduce your risk of Claude token theft:

  • Use strong, unique passwords for your Claude account

  • Enable two-factor authentication whenever available

  • Avoid downloading software from untrusted sources

  • Be cautious with ads and avoid clicking on suspicious links

  • Monitor your token usage regularly for unusual patterns

  • Log out of sessions when not actively using Claude

  • Consider using a password manager to reduce exposure to infostealer malware

When Claude token theft occurs, users face significant disruption and financial loss. The lack of detailed usage tracking makes detection difficult, and recovery can take weeks. As AI tools become increasingly central to business operations, understanding and protecting against Claude token theft becomes essential for every subscriber.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *