Tech news in 3 minutes
Hackers are stealing Claude tokens from subscribers
Anthropic's Claude AI faces a security breach as hackers use infostealer malware to steal session tokens and drain user accounts, raising concerns about token theft and lack of usage transparency. On August 4, independent AI consultant Grant De Swardt noticed unexplained token consumption on his Claude Max 20x account. After disabling all integrations, token usage still rose from 45% to 55% while idle. Anthropic suspended his account, invalidated sessions, and issued a partial £44.49 refund, but could not provide an itemized usage list. Investigation revealed a compromised Claude session key was used to mint unauthorized OAuth tokens by a third party. De Swardt's experience echoed on Reddit and GitHub, where multiple users reported similar unauthorized usage. Anthropic later acknowledged a "bad actor using common infostealer malware to steal Claude login sessions" and warned affected users. The malware, not originating from Claude itself, can be acquired from infected downloads or ads. De Swardt found no evidence of his own computer being compromised. After two weeks, his account was reinstated, but he canceled his subscription for Cursor, citing Anthropic's lack of itemized usage tools and difficulty getting help. He stated, "I don’t think there’s any way that these people can protect themselves." Anthropic declined to comment on user identification of misuse. The incident highlights critical security gaps in AI token management and the need for better monitoring tools.