AiPhreaks ← Back to News Feed

Hackers are stealing Claude tokens from subscribers

By Jakub Antkiewicz

•

2026-09-09T12:46:05Z

Subscribers to Anthropic's paid Claude AI services are reporting that their accounts are being compromised, leading to rapid, unexplained token consumption and direct financial loss. The issue gained prominence after consultant Grant De Swardt documented his token allowance being drained despite his account being inactive. This string of incidents highlights a critical vulnerability for users who rely on these powerful AI tools for their business operations, exposing a significant gap in account security and monitoring capabilities on a major AI platform.

Anthropic has since confirmed that attackers are deploying infostealer malware to hijack user login sessions. This type of malware, typically contracted from infected downloads or ads, steals saved credentials and session data from a user's computer. The bad actor then uses the stolen session to mint unauthorized OAuth tokens and consume the victim's usage quota. While Anthropic has proactively warned some users and issued partial refunds, the platform's inability to provide an itemized breakdown of token usage makes it exceptionally difficult for subscribers to detect or verify unauthorized activity on their own.

Key Aspects of the Token Theft

  • Attack Method: Use of common infostealer malware to steal Claude login sessions from a user's computer.
  • User Impact: Rapid and unexplained depletion of monthly token allowance, leading to service disruption and financial loss.
  • Platform Vulnerability: A lack of user-facing tools, such as itemized usage logs, to monitor and audit token consumption.
  • Company Response: Account invalidation, partial refunds, and user warnings, but no fundamental changes to account monitoring tools have been announced.

The security lapse and lack of transparency are creating a trust deficit that could have broader market implications. For developers and businesses integrating AI into core processes, the inability to audit compute consumption is a major liability. De Swardt's decision to cancel his subscription and switch to multi-model platforms like Cursor demonstrates that customers will migrate to services that offer greater control, security, and transparency. This incident serves as a clear signal to the industry that robust account security and detailed auditing features are no longer optional—they are essential for retaining professional users.

As AI platforms become mission-critical business utilities, providers must move beyond simply offering powerful models and prioritize user-facing security controls. The absence of basic features like itemized billing and session management creates an unacceptable risk, forcing customers to question the viability of building their operations on such platforms.
End of Transmission
Scan All Nodes Access Archive