Hackers are stealing Claude tokens from subscribers
techcrunch.com Sep 8, 2026

Hackers are stealing Claude tokens from subscribers

AI-summarised brief · reviewed before publication

Independent AI consultant Grant De Swardt discovered unauthorized token consumption on his Claude Max 20x account, prompting an investigation by Anthropic. The company identified that compromised session keys allowed hackers to mint unauthorized OAuth tokens, siphoning usage without the user’s knowledge. Anthropic suspended De Swardt’s account, invalidated sessions, and issued a partial refund, though he suffered business disruption. Similar reports emerged on Reddit and GitHub, with users citing sudden, unexplained usage spikes. Anthropic confirmed that infostealer malware was harvesting login credentials from infected computers, not from Claude itself. The company warned affected users and invalidated authorizations. However, the lack of itemized usage tracking made detection difficult. De Swardt, finding no malware on his own system, canceled his subscription. He switched to Cursor, citing better support and access to affordable open-source models. He stated he would not return to Anthropic until they resolve these security and transparency issues, highlighting a growing concern over account security in AI services.

💡 Why It Matters

  • · The incident exposes a critical vulnerability where infostealer malware can silently drain paid AI subscriptions, turning user accounts into resources for unauthorized third parties.
  • · This lack of granular usage transparency forces professionals to abandon trusted platforms for competitors offering better security controls and cost efficiency.