Hackers Stealing Claude Tokens: A Growing Threat to AI Subscribers

Hackers are increasingly targeting AI subscription accounts, and Anthropic's Claude platform has become a prime target in 2026. A wave of incidents reveals that malicious actors are stealing Claude tokens from subscribers, siphoning off usage allowances and leaving victims with depleted accounts, unexpected charges, and compromised workflows. On August 4, 2026, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed something unusual with his Claude Max 20x account. Despite not working that day, his token usage was climbing. The next day, he disabled all integrations and avoided using Claude entirely—yet token consumption still increased. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” de Swardt told TechCrunch. Puzzled and concerned, de Swardt contacted Anthropic, requesting an itemized breakdown of his usage. Anthropic did not provide one but acknowledged that something was amiss. The company suspended his paid account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription. The suspension had a cascading effect on his business. As a sole proprietor, de Swardt helps small and medium enterprises set up AI agents—essentially acting as a forward-deployed engineer for hire. His projects include automating purchase-order data extraction from emails into accounting software. But his reliance on AI extended beyond client work. “Daily admin tasks, website design, coding—like everything is just running through AI these days,” he explained. The disruption meant lost productivity and halted operations while Anthropic investigated. After a thorough review, Anthropic traced the issue to a compromised Claude session key. This key was used to mint unauthorized Claude Code OAuth tokens. The company informed de Swardt that his account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access,” he said. “They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.” In short, a hacker had accessed de Swardt's account and quietly drained his tokens. Because Anthropic's support system tracks total usage but not itemized usage—even upon request—such theft could remain undetected for months. De Swardt shared his experience on Reddit, and within 80 comments, he discovered he was far from alone. One user reported that their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another noticed usage jumping from 0% to 49% in just 12 minutes, despite only using Claude for a few prompts and web searches. A third user described how their account burned through its maximum token allowance every day for three consecutive days without any activity on their part, prompting them to file a GitHub report. Others chimed in with similar experiences, corroborating a pattern of unauthorized token consumption. Encouragingly, some users shared emails from Anthropic in which the company proactively identified and warned them about token theft. In these cases, Anthropic took corrective action, but the underlying vulnerability persists. Security experts point to infostealer malware as a primary vector. These malicious programs harvest login session tokens and credentials from infected devices, allowing attackers to bypass traditional two-factor authentication. Once stolen, these tokens can be used to generate OAuth tokens and access AI services without detection. As AI subscriptions become more integral to business operations, protecting these accounts is critical. Subscribers should regularly monitor usage metrics, enable multi-factor authentication where possible, and avoid connecting third-party services that may require broad permissions. Meanwhile, platforms like Anthropic must improve transparency, offering itemized usage logs and real-time alerts to help users detect anomalies early. For now, de Swardt's story serves as a cautionary tale. In an era where AI drives everything from coding to customer service, a stolen token isn't just a financial inconvenience—it's a potential business stopper.

via TechCrunch

Related