Hackers used stolen sessions to drain Claude Max 20x tokens

On August 4, an independent AI consultant in East Sussex observed rising token usage on his Claude Max 20x account despite not working that day. The following day he disabled connected services and paused scheduled tasks, yet token consumption rose again from 45% to 55% in a controlled interval, he said.

Investigation and account actions

The consultant asked Anthropic for an itemized usage list; the company did not provide one but agreed activity looked abnormal. Anthropic suspended the paid account, invalidated sessions and server-side Claude Code tokens, and refunded £44.49 for the remaining time on the $200-per-month subscription.

Anthropic later told him that a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. The company said the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people,” and that evidence was consistent with either credentials or session data being taken without his knowledge or the account having been connected to an outside service, he reported.

Similar reports and malware link

After sharing the experience online, the consultant found others reporting sudden spikes in usage, auto-upgrades, and rapid token depletion. Some users posted emails from Anthropic warning that a bad actor was using common infostealer malware to steal Claude login sessions from infected computers, then accessing accounts to consume usage. Infostealers capture saved passwords, session data and credentials and can arrive via infected downloads or malicious ads, the company said in those notices.

The consultant says Anthropic did not send him such an email and that he found no evidence his computer was compromised. His account was reinstated after about two weeks. He canceled the subscription and switched to Cursor, citing its ability to use multiple models and lower-cost open-source options, and said he believed other models worked as well as Claude. He added he could not see returning without a clear resolution and that he saw no way for users to protect themselves.

When asked for information on how users can identify misuse, Anthropic declined to comment.


Original source: TechCrunch AI

Leave a Comment