Hackers are stealing Claude tokens from subscribers
TechCrunch Julie Bort
Hackers are hijacking Claude logins and burning subscribers’ token limits. Anthropic’s own support can’t show itemized usage, so the theft can stay hidden.
Based on reporting by TechCrunch, Julie Bort — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
A UK AI consultant spotted something odd in his Claude Max 20x account on August 4: his token use kept rising even when he wasn’t using it. He checked again the next day after disabling everything attached to Claude. The count still climbed. Anthropic later suspended the account, wiped the sessions and server-side Claude Code tokens, and refunded him £44.49 on a $200-a-month plan.
The user, Grant de Swardt, says the hit wasn’t just annoying. He runs a small business helping other companies set up agents for chores like pulling purchase-order data out of email and sending it into accounting software. He also leans on AI for his own admin, web work, and coding, so losing access cut straight into his workday. He told TechCrunch that, once the account was suspended, the disruption “wreaked havok” on the business.
Anthropic eventually told him what it believed happened: a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. In plain English, someone got into the account without permission and quietly spent the tokens. The company said the account looked like it may have been used by “an unauthorized-looking third-party service,” but it could not figure out how that access was obtained.
The ugly part is how invisible this can be. Anthropic support tracks total usage, but not an itemized breakdown, even when users ask for one. That means someone could drain an account for a long time before the owner notices. De Swardt says he still has no proof his own computer was compromised, and he says Anthropic never sent him the warning email it sent to other users in similar cases.
Those other cases sound familiar. On Reddit, one user said their account was auto-upgraded and charged without consent, while usage jumped from 0% to 100%. Another said usage jumped from 0 to 49% in 12 minutes. Anthropic told some users that bad actors were using infostealer malware to steal Claude login sessions from computers, then using those sessions to access accounts and burn through usage. It also said the malware did not come from Claude itself.
My take — AI-written commentary, not fact-checked reporting
This is the kind of bugaboo that turns a subscription into a hostage situation. If a company meters usage but won’t show users where it went, the customer is basically left staring at a mystery bill and a very expensive shrug. Plenty of AI vendors talk about trust; this is where it gets tested.
Read more about this at: TechCrunch