Hackers Steal Claude Tokens From Subscribers as Anthropic Warns Users

Share

Hackers are reportedly targeting Claude subscribers, secretly using compromised account sessions to consume users’ AI token allowances without their knowledge. The issue came to light after Grant De Swardt, an independent AI consultant in East Sussex, UK, noticed his Claude Max 20x account using up tokens even though he had stopped working with the AI platform.

De Swardt said his token usage continued rising even after he disabled the tools connected to Claude and paused scheduled tasks. After contacting Anthropic, the company suspended his paid account, invalidated his active sessions and Claude Code tokens, and refunded £44.49 for the unused portion of his $200 monthly subscription. Anthropic later told him that a compromised session key had been used to create unauthorized Claude Code OAuth tokens.

The incident appears to be part of a wider problem. After De Swardt shared his experience on Reddit, other Claude users reported similar cases, including accounts whose token allowances reportedly jumped from little or no usage to 100% without the owners actively using the service. Some users also reported unexpected charges and rapid consumption of their token limits.

Anthropic has since warned some affected customers that attackers may be using infostealer malware to steal Claude login sessions from users’ computers. This type of malware can capture saved passwords, session information and other login credentials, potentially allowing attackers to access online accounts. Anthropic said the malware was not caused by using Claude itself and could come from other infected software, websites or advertisements.

For affected users, the incident has raised concerns about account security and the lack of detailed token-usage information. De Swardt’s account was eventually restored after about two weeks, but the experience led him to cancel his Claude subscription and move to another AI coding platform. The case highlights the growing need for AI users to secure their accounts, monitor unusual activity and have clearer tools for tracking exactly how their paid usage is being consumed.

source: techcrunch 

Leave a Reply

Your email address will not be published. Required fields are marked *