Technology

Hackers Are Stealing Claude Tokens From Paying Subscribers

Paid Claude accounts are being drained by people who never typed the password.Anthropic has told affected subscribers that a threat actor is using common infostealer malware to copy live Claude login sessions off infected computers, then replay those sessions to consume usage. The company is not describing a breach of its own servers. It is describing theft from the user’s machine: cookies and session material that already prove someone is logged in.If your quota seemed to refill and then empty while you were not using Claude, that is the pattern Anthropic named in emails sent to customers.The response so far is blunt. Anthropic has signed victims out everywhere, invalidated sessions and some Claude Code tokens, removed saved payment methods, and refunded charges it classified as unauthorized. Plans already paid for continue through the current billing period. To buy anything after that, the user must add a card again.Grant De Swardt, an independent consultant in East Sussex, watched his Claude Max 20x meter climb on a day he did no work. He shut down attached tools. Usage still rose — in one window, from 45 percent to 55 percent with no local Claude Code job and no scheduled tasks running. Anthropic agreed something was wrong, suspended the paid account, killed sessions and server-side tokens, and refunded £44.49 on a $200-a-month plan. Later it told him a compromised session key had been used to mint unauthorized Claude Code OAuth tokens.Other users posted similar Anthropic emails on Reddit. The wording is consistent: malware on the PC, stolen sessions, burned usage, card removed as a precaution.What Was StolenThis is not a clever guess of a password. Multi-factor at the login box does not help if the attacker never sees the login box.A browser keeps a session after you sign in so you are not asked for a password on every click. Infostealers copy that session along with other loot — saved passwords, cookies, tokens for whatever else is open. Someone later sorts the dump for Claude sessions and uses them.Anthropic has named families already known to security teams: Vidar, LummaC2 (Lumma), StealC, RedLine, and Acreed on Windows, and Atomic Stealer on a smaller number of Macs. None of those tools was built only for Claude. They grab whatever the infected machine holds. Claude became valuable once Max plans, extra usage credits, and coding agents made a hijacked session worth real money.Windows is the bulk of the cases described. Macs appear in the same campaign. Phones and tablets have not been cited as sources.Self-serve accounts billed to a personal card are the population in the emails. Those accounts often sit outside a company SSO console. An IT admin cannot remotely kill a session they never issued. Cookie replay skips the login page that 2FA protects.Why Tokens Are the PrizeClaude Max and extra usage are expensive by design. A stolen session lets someone else run agents, coding loops, and long chats on the victim’s tab. If auto-reload or prepaid credits are on, the meter can keep buying.The motive is free compute. Paid Claude capacity can draft phishing, shape malware, sort stolen data, or simply resell access. The account itself may also expose connected mail, files, or OAuth grants that were never meant to leave a laptop. Venture reporting has flagged that some Claude-linked grants can reach corporate Gmail in ways a typical admin revoke list does not cover. Burned tokens are the visible loss. Reach into other apps is the quieter one.De Swardt’s case is the professional version of the same problem. His whole shop runs through agents — admin, design, code. A silent drain is not a hobby inconvenience. It is a business outage plus a bill.Anthropic did not publish an itemized token log for him on first request. Detection came from usage that made no sense. That gap — customers cannot easily see who spent what — is part of why people only notice when the bar jumps overnight.What Anthropic Has DoneCredit where it is due: the company is mailing victims, naming malware families, killing sessions, pulling cards, and refunding bad charges. It has said it may sign people out again if the same pattern returns.That last line matters. Signing out cancels the stolen copy of the session. It does not clean the computer. If the stealer is still there, the next login can be copied again.Anthropic has been careful to separate this from a hole in Claude’s own product. The infection path it describes is the usual one: unofficial downloads, cracked software, malicious installers. Claude is one more item in the grab bag.A parallel gray market in cheap “Claude-compatible” API access has existed for months, sometimes built on abused cloud credits. This campaign is different. It rides real subscriber sessions rather than fake promotional accounts. Both shrink Anthropic’s control over who is actually talking to the model.What Subscribers Should AssumeTreat a surprise usage spike as a security event, not a billing glitch.Check whether Anthropic has mailed you. If you were signed out and your card vanished from the account, that is the containment play, not a random outage.Assume the laptop is dirty until it is rebuilt or thoroughly cleaned. Changing the Claude password on an infected machine is not a full fix. The next session can be stolen the same way.Turn off auto-reload until you know the device is clean. Watch extra usage credits. Review connected apps and OAuth grants. If Claude can see mail or drives, treat those as in scope.Companies that let staff use personal Max plans for work have a messier problem. There is no tenant admin button for a consumer session cookie. Policy has to be: no paid AI accounts on unmanaged PCs, or accept that a stealer on a designer’s laptop is now a cloud-spend and data problem.The Larger ShiftAI subscriptions are becoming bank accounts with a chat window. Criminals already steal streaming logins and game accounts. A $200 Claude Max tab that can write code all night is a better target.The industry spent years arguing about model jailbreaks and prompt injection. Endpoint theft is older and duller. It works. Infostealers do not need to beat Claude’s safety stack. They need the user to install one bad file.Anthropic can detect odd usage and slam the door. It cannot scan every customer PC. Until session design, device binding, and spending alerts catch up, paying users are the perimeter.De Swardt got a partial refund and a dead session. He still has to trust that the next login is only his. That is the state of consumer AI security in September 2026: the model is sophisticated, and the lock is a cookie on a laptop that downloaded the wrong thing.

Comments (0)

Please log in to comment

No comments yet. Be the first!