Anthropic has confirmed a security breach affecting Claude Max subscribers, with hackers using infostealer malware to steal login sessions and drain tokens. Multiple users report unauthorized token usage climbing to 100% without any activity, forcing account suspensions and business disruptions.

Hackers Stealing Claude Tokens Through Compromised Session Keys

Anthropic has confirmed a significant security breach affecting its Claude Max subscribers, with hackers using infostealer malware to steal login sessions and drain tokens from paying customers. The issue came to light when Grant de Swardt, an AI consultant in East Sussex, UK, noticed his Claude Max 20x account token usage climbing from 45% to 55% despite performing no work on August 4

1

. After disabling all attachments and pausing scheduled tasks, unauthorized token usage continued to escalate, revealing a pattern of account hijacking that has affected multiple subscribers.

Source: CXOToday

Source: CXOToday

Anthropic investigated and determined that compromised session keys were being used to mint unauthorized Claude Code OAuth tokens

2

. The company told de Swardt his account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access." This revelation exposed a critical vulnerability in how Claude tokens are being protected, with hackers covertly siphoning off resources from $200-per-month subscriptions without detection.

Multiple Claude Max 20x Account Holders Report Unauthorized Token Usage

After de Swardt posted his experience on Reddit, more than 80 comments revealed he wasn't alone in experiencing this security breach

3

. One user reported their account was auto-upgraded without consent, their credit card charged, and usage shot from 0% to 100% automatically. Another Claude subscriber saw usage jump from 0% to 49% in just 12 minutes after only a couple of prompts and a web search. A GitHub report documented an account that burned through maximum tokens daily for three consecutive days despite no actual usage, with other users sharing similar experiences in the thread.

The pattern of unauthorized token usage suggests a coordinated effort by bad actors targeting Claude Max subscribers specifically. Because Anthropic's account support tracks only total usage and not itemized usage—even upon request—this type of token theft could continue for months undetected. Users have no way to see what's consuming their tokens or identify suspicious activity until their allowance is completely drained.

Anthropic Confirms Infostealer Malware Behind Login Sessions Theft

In emails sent to affected users, Anthropic acknowledged the security breach and explained the attack vector. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," the company wrote

1

. Infostealer malware installs itself on users' computers and steals saved passwords, session data, and login credentials, allowing hackers to hijack accounts without needing actual passwords.

Source: TechCrunch

Source: TechCrunch

Anthropic clarified that the malware didn't originate from using Claude itself but could be picked up from various online sources, including infected software downloads or malicious ads. When the company detected suspicious activity, it signed users out, invalidated existing authorizations, and issued partial refunds. However, de Swardt insists he found no evidence his computer was compromised and received no warning email from Anthropic, leaving him unable to determine how hackers gained access to his account

2

.

Business Disruption Forces AI Consultant to Abandon Claude

The account suspension wreaked havoc on de Swardt's business as an independent AI consultant who helps small and mid-size businesses set up AI agents for tasks like automatically loading purchase-order data from emails into accounting software

1

. As a sole proprietor, he relies on AI agents throughout his entire operation for daily admin tasks, website design, and coding. "Like everything is just running through AI these days," he explained.

After his account was reinstated following a two-week suspension, de Swardt cancelled his subscription and switched to Cursor, which offers the ability to use multiple models, including more affordable open-source options. The difficulty of getting speedy help, combined with the lack of itemized usage data and token management tools, soured him on Claude entirely. "I don't think there's any way that these people can protect themselves," he said, noting that Anthropic still lacks tools allowing users to see what's consuming their tokens. He received a partial refund of £44.49 for the remaining time on his $200-per-month subscription

3

.

AI Tool Security Concerns Raise Questions About User Protection

This security breach highlights broader concerns about AI tool security as businesses increasingly rely on AI agents for critical operations. The inability to track itemized usage or detect unauthorized activity in real-time leaves subscribers vulnerable to ongoing theft. When asked how users can identify misuse of their accounts, Anthropic declined to comment

2

, leaving customers without clear guidance on protecting themselves from future attacks.

The incident raises questions about what safeguards AI companies should implement to protect subscribers from account hijacking and unauthorized token usage. Without transparent token management systems or detailed usage logs, users have no way to audit their accounts or catch suspicious activity early. As AI tools become essential business infrastructure, the lack of robust security measures and user-facing monitoring tools could undermine confidence in paid AI services. The compromise of Claude tokens through stolen login sessions demonstrates that even sophisticated AI platforms remain vulnerable to basic security threats like infostealer malware, forcing companies to balance accessibility with protection against bad actors exploiting compromised session keys.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved