Stolen Claude Sessions Trigger Unauthorized Token Use

Anthropic identifies session theft behind Claude token drain
Anthropic has warned Claude users that a bad actor used infostealer malware to steal login sessions and consume usage on affected accounts. The issue came to light after Grant de Swardt, an independent AI consultant in East Sussex, found unexplained activity on his Claude Max 20x subscription, priced at $200 a month.
In a controlled period on August 4 and 5, de Swardt said his token usage climbed from 45% to 55% despite his doing no work. Scheduled Cowork tasks were paused or complete, Dispatch and cloud execution were disabled, and there was no active local Claude Code task. Anthropic suspended the account, invalidated its sessions and server-side Claude Code tokens, and gave a partial £44.49 refund.
Following its investigation, Anthropic told de Swardt that a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. It said the account appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, while it could not establish how access had been obtained.
Limited usage visibility complicates detection
De Swardt requested an itemized record of use, but Anthropic did not provide one. Support could track total consumption rather than a detailed breakdown, leaving the account holder without a direct way to establish what was using the allowance. He said this could allow theft to continue unnoticed for an extended period.
Other users reported comparable patterns in Reddit comments and a GitHub report, including token allocations rising rapidly when they had made little or no use of Claude. Two users shared emails in which Anthropic said it had identified suspicious consumption and warned that common infostealer malware was stealing Claude login sessions from computers.
Infostealers can collect saved passwords, credentials and session data from infected machines. Anthropic said the malware was not acquired through Claude itself and can originate from sources such as infected software downloads or malicious advertisements. When it detected suspicious activity, the company said it signed users out, invalidated existing authorizations, issued some refunds and warned them about possible malware.
Security controls matter as AI accounts enter operations
The incident has particular consequences for businesses using AI services in operational workflows. De Swardt uses agents for customer projects, administrative work, website design and coding; the broader commercial relevance is reinforced by Claude’s expanding paid-user base as Claude’s paid-user base expands.
His account was restored after about two weeks, but he cancelled the subscription, citing the support experience and the absence of tools showing what consumed tokens. For organisations, unexplained AI usage should be handled as a possible credential compromise: revoke active sessions and authorizations, review connected services, and investigate affected endpoints before resuming dependent workflows.

