AI

Malicious Actors Are Hijacking Anthropic Claude Accounts to Drain Paid Token Allowances

Infostealer malware and compromised session keys leave subscribers facing depleted allowances and opaque usage metrics

  • Hackers are quietly intercepting login session credentials from Anthropic customers, siphoning paid computing allowances to power unauthorized third-party workloads, according to a report by TechCr…
  • The vulnerability came to light after Grant De Swardt, an independent AI consultant based in East Sussex, U.K., observed unexplained consumption surges on his $200-a-month Claude Max 20x plan on Au…
  • Anthropic subsequently informed De Swardt that an unauthorized entity had leveraged a compromised session key to generate rogue Claude Code OAuth tokens.
Malicious Actors Are Hijacking Anthropic Claude Accounts to Drain Paid Token AllowancesThe Scale Report

Hackers are quietly intercepting login session credentials from Anthropic customers, siphoning paid computing allowances to power unauthorized third-party workloads, according to a report by TechCrunch. The illicit activity has left subscribers blindsided by rapid quota depletion on premium tiers.

The vulnerability came to light after Grant De Swardt, an independent AI consultant based in East Sussex, U.K., observed unexplained consumption surges on his $200-a-month Claude Max 20x plan on August 4. Despite halting scheduled tasks, local scripts, and cloud execution, his account meter climbed steadily during a controlled observation period. When he flagged the anomaly, Anthropic locked his account, revoked active sessions and server-side Claude Code tokens, and issued a partial refund of £44.49.

Anthropic subsequently informed De Swardt that an unauthorized entity had leveraged a compromised session key to generate rogue Claude Code OAuth tokens. In separate alerts sent to affected users who voiced concerns on Reddit and GitHub, the AI company attributed the intrusions to infostealer malware. This malicious software harvests stored credentials and active browser sessions directly from infected computers, enabling external actors to tunnel through legitimate user subscriptions.

As high-tier model access becomes an expensive commodity, stolen API authorizations and session tokens represent an increasingly lucrative target for proxy services and unauthorized compute arbitrage. The integration of automated coding agents and persistent background execution expands the attack surface, creating new security risks for solo developers and enterprise practitioners alike.

The incidents also underscore a persistent transparency issue within AI developer platforms. Anthropic does not currently provide customers with itemized, real-time activity logs. Without granular telemetry detailing prompt origins and IP addresses, subscribers have few native tools to differentiate between runaway internal workloads and external credential theft.

Following a two-week disruption to his operations, De Swardt canceled his Claude subscription and transitioned his workflow to developer platform Cursor, citing the availability of alternative models and the unresolved visibility limitations. When questioned about future tools to help users audit suspicious consumption, Anthropic declined to comment.

Reporting based on coverage from AI News & Artificial Intelligence | TechCrunch.

The daily brief

The biggest stories in AI, venture, sports business and culture - once a day.

One short email from The Scale Report. No spam, unsubscribe any time.

Read next