anthropic

Stolen session keys are draining Claude Max accounts

Claude News

anthropic

Attackers are draining paid Claude subscriptions with stolen login sessions: independent AI consultant Grant De Swardt watched his Claude Max 20x usage climb from 45% to 55% during an interval in which he ran no tasks at all. He described the case to TechCrunch, and Anthropic later traced it to a compromised session key.

At a glance

  • Anthropic told De Swardt that a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens, and that it could not determine how the account was accessed.
  • Other subscribers described the same pattern on Reddit and GitHub: one reported usage jumping from 0 to 49% in 12 minutes after a couple of prompts and a web search.
  • Account support tracks total consumption but not itemized usage even on request, so token theft can continue undetected, and De Swardt's suspended account took about two weeks to come back.

The Claude subscription plans sell a usage allowance, not a log: support can see how much of it is gone but not what spent it, which leaves a stolen session indistinguishable from heavy legitimate work. That gap appears to be what makes this class of theft worth running at all, since the account holder's only signal is a percentage moving on its own. For agent-heavy workflows, where consumption is erratic by design, the signal is weaker still.

Usage rose from 45% to 55% while every integration was switched off

De Swardt noticed the anomaly on August 4, when his token consumption on the Max 20x plan kept climbing on a day he had not worked. The following day he disabled everything attached to Claude and stayed away from it, and consumption rose again.

In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task.

He asked Anthropic for an itemized list of what had consumed the allowance. The company did not supply one, but agreed that something was wrong: it suspended the paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on the $200-per-month plan.

The suspended account came back after about two weeks

De Swardt told TechCrunch that the suspension wreaked havoc on his business. As a sole proprietor in East Sussex, he sets up agents for small and mid-size businesses, handling tasks such as loading purchase-order data from emails into accounting software, and leans on the same tools for admin, website design and coding.

Anthropic's investigation pointed to a compromised Claude session key that had been used to mint unauthorized Claude Code OAuth tokens. According to De Swardt, the company said the account appeared to have been used by an unauthorized-looking third-party service handling activity for other people, and that it could not establish how that access was obtained.

The evidence, he said Anthropic told him, was consistent either with credentials and session data being taken without his knowledge or with the account having been connected to an outside service. His paid account was reinstated after roughly two weeks of downtime.

Anthropic warned other users that infostealer malware was taking Claude sessions

De Swardt posted his experience on Reddit, and about 80 comments later he found he was not alone: one user said their account was auto-upgraded without consent, their card charged, and usage jumped from 0% to 100% untouched. Another reported max tokens burned daily for three days and filed a GitHub report, where two users posted warning emails from Anthropic.

We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.

Infostealer malware installs itself on a computer and harvests saved passwords, session data and login credentials, and it can arrive through infected software downloads or malicious ads. Anthropic signed the affected users out, invalidated existing authorizations, issued some refunds, warned them about the malware, and said it did not come from using Claude.

The Max plan traded for Cursor

De Swardt says he found no evidence that his own computer was compromised and was not among the users who received one of those emails, and he still has no way to see what consumes his tokens. He cancelled the Max subscription for Cursor and its choice of models, including cheaper open source ones, which he says work about as well, and does not plan to return until Anthropic resolves the issue.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.