THREAT ASSESSMENT: Paid Claude subscribers are getting their tokens stolen, and most have no way to see it happening. TechCrunch AI reports that a bad actor is using infostealer malware to hijack Claude login sessions, then burning through victims’ usage while they sit idle. Anthropic has confirmed the pattern and started warning affected users directly.
Here is the situation on the ground.
🎯 Patient Zero
On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., watched his Claude Max 20x usage climb while he did no work at all. He disabled everything attached to the account. Consumption kept rising anyway. In one controlled window, his allowance jumped from 45% to 55% with no active task running, he told TechCrunch AI.
He asked Anthropic for an itemized breakdown. The company couldn’t produce one. Account support tracks total usage, not line-by-line usage, even on request. That single gap is the whole problem: theft like this can run for months undetected.
🔍 Confirmed Findings
Anthropic investigated and reported back to De Swardt. The tactical picture:
- A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens.
- The account looked like it was being used by an unauthorized third-party service handling activity for other people.
- Anthropic could not determine how the attacker got in.
The fix on their end was blunt but effective. Suspend the account, invalidate all sessions and server-side tokens, issue a partial refund. De Swardt got £44.49 back on his $200-a-month plan and lost about two weeks of access. As a sole proprietor who runs admin, coding, and client agent builds through AI, the suspension hit his business hard.
📡 This Is Not An Isolated Case
De Swardt posted to Reddit and found company. Per TechCrunch AI’s reporting, the reports stack up:
- One user’s account was auto-upgraded without consent, their card charged, and usage shot from 0% to 100% without a single keystroke.
- Another watched usage climb 0 to 49% in 12 minutes after only a couple of prompts and a web search.
- One account burned through its max tokens daily for three straight days of zero use, then filed a GitHub report where still more victims surfaced.
Two users posted the email Anthropic sent them. The company’s own words: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.”
🦠 Know The Weapon
Infostealers are malware that quietly install on your machine and lift saved passwords, session data, and login credentials. Anthropic says the malware does not come from using Claude. You pick it up the usual ways: infected downloads, malicious ads, sketchy software. Once it grabs a live session token, the attacker doesn’t need your password or your two-factor code. They just ride the session you already opened.
⚠️ Why This Matters
What stands out here is the visibility gap, not just the malware. When your provider can’t tell you what consumed your tokens, you can’t tell theft from normal use until the bill or the usage bar spikes. Credit to Anthropic for spotting some cases and warning users. But De Swardt never got that warning, found no evidence his own machine was compromised, and still can’t explain the breach. He cancelled Claude for Cursor, which lets him mix in cheaper open source models. When TechCrunch AI asked Anthropic how users can spot misuse themselves, the company declined to comment.
🛡️ Immediate Orders
- Run a reputable malware scan now, especially if your usage looks off.
- Sign out of all Claude sessions and rotate any Claude Code tokens if you see unexplained consumption.
- Watch for surprise plan upgrades or charges.
- Assume session tokens are as sensitive as passwords, because to an infostealer they’re better.
Until providers give users itemized usage and a real kill switch, session hijacking stays a quiet, profitable attack. Full reporting is available at the original source.