Infostealer malware drains Claude subscribers' tokens — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed his $200/month Claude Max 20x tokens climbing on August 4 despite not working that day; Anthropic eventually confirmed a "compromised Claude session key" had been used to mint unauthorized Claude Code OAuth tokens.
- Anthropic suspended De Swardt's account, invalidated all his sessions and server-side Claude Code tokens, and issued a £44.49 partial refund — but did not provide itemized usage data even after he requested it.
- After posting on Reddit, De Swardt found he wasn't alone: one user reported being "auto-upgraded without my consent" with a credit card charge and usage jumping to 100%; another saw usage spike from 0% to 49% in 12 minutes; a third burned through max tokens for three straight days without touching the account.
- Two affected users received emails from Anthropic warning that "a bad actor" was using common infostealer malware to steal Claude login sessions from people's computers — the company signed them out, invalidated authorizations, and issued refunds.
- Anthropic said the malware didn't originate from Claude itself but from sources like infected software downloads or malicious ads, and declined to comment when asked how users can identify ongoing misuse.
- De Swardt cancelled his Claude subscription in favor of Cursor, saying "I don't think there's any way that these people can protect themselves" without visibility into what is consuming their tokens.
Why it matters: Subscribers on $200/month plans discovered their tokens being drained by hackers using stolen login credentials, with Anthropic's lack of itemized usage logs letting theft persist undetected for months; at least one victim publicly abandoned the platform for Cursor, posing a concrete retention and trust risk as Anthropic courts enterprise customers.
Ask SkimNews



