Hackers Siphon Claude Tokens via Stolen Sessions — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Grant De Swardt, an AI consultant in East Sussex, noticed his Claude Max 20x tokens climbing on August 4 while he wasn't working; Anthropic later confirmed a compromised session key had minted unauthorized Claude Code OAuth tokens in his name.
- Anthropic suspended De Swardt's paid account, invalidated all sessions, and issued a partial refund of £44.49 on his $200/month subscription, but provided no itemized usage breakdown — meaning token theft can go undetected for months.
- Other Claude subscribers reported similar token drain on Reddit and GitHub, including one account jumping from 0% to 49% usage in 12 minutes and another burning through max tokens daily for three days without activity.
- Anthropic identified the culprit as infostealer malware that steals saved passwords and session data from users' computers, then signs affected users out, invalidates authorizations, and warns them of possible compromise.
- De Swardt's account was reinstated after roughly two weeks, but he cancelled his Claude subscription in favor of Cursor, citing the inability to track token consumption and saying other models perform comparably.
- Anthropic declined to comment when asked how subscribers can identify ongoing misuse, leaving users without a self-serve tool to detect theft on their own accounts.
Why it matters: Subscribers on Anthropic's top-tier $200/month Claude Max 20x plan are absorbing the cost of stolen token usage — De Swardt lost roughly a quarter of a month's subscription to fraud — while the platform offers no itemized usage tracking to detect it. The pattern repeats across multiple users, suggesting a campaign rather than an isolated incident, yet Anthropic provided no user-facing detection tool and declined to comment on remediation.
Ask SkimNews



