Key facts
- Hackers are stealing Claude AI tokens by exploiting compromised session keys.
- Infostealer malware is used to steal user login sessions and access Claude accounts.
- Anthropic identified unauthorized third-party activity on affected accounts.
- Affected users experienced unexpected token consumption and unauthorized account upgrades.
- Anthropic suspended accounts, invalidated sessions, and issued partial refunds to some users.
AI consultant Grant de Swardt discovered that his Claude Max account was being used without his knowledge, consuming his token allowance. After contacting Anthropic, his account was suspended and he received a partial refund. Anthropic identified that a compromised Claude session key was used by unauthorized third parties to mint and use tokens.
De Swardt's experience was not isolated, as other Claude users reported similar issues, including unauthorized account upgrades and rapid token consumption. Anthropic confirmed that hackers are using infostealer malware to steal user login sessions and access their Claude accounts. The company stated that the malware does not originate from Claude itself but can be acquired from various online sources.
Anthropic took action by signing out affected users, invalidating authorizations, and issuing refunds. De Swardt's account was eventually reinstated, but he canceled his subscription, citing a lack of transparency in usage tracking and difficulty in resolving the issue. He expressed that users currently lack the tools to protect themselves from such misuse.
