anthropic

Stolen session keys drained Claude token quotas

Promtime

anthropic

Anthropic told Claude Max 20x subscriber Grant De Swardt that a compromised session key had been used to mint unauthorized Claude Code OAuth tokens on his account, draining the usage allowance on his $200-per-month plan while he did no work, as reported by TechCrunch.

At a glance

  • Other subscribers described the same pattern on Reddit and GitHub, including one whose meter went from 0 to 49% in 12 minutes after a couple of prompts and a web search.
  • Anthropic emailed some affected users about a bad actor using common infostealer malware to steal Claude login sessions from computers, then using those sessions to consume account usage.
  • Anthropic's account support tracks total consumption but not itemized usage, even on request, so a covert drain on a paid plan can continue for months before anyone notices it.

Metered AI subscriptions turn a stolen session into direct spend, and this case reads as a gap in accounting rather than in security alone: the meter shows a percentage consumed without showing what consumed it. For a sole proprietor running client agents through the same account, that likely matters more than the refund, since the remedy on offer was suspension of the account itself.

Usage climbed from 45% to 55% during an interval with no work

De Swardt, an independent AI consultant in East Sussex, U.K., noticed the drain on August 4, a day he had not been working, and watched his token usage keep climbing. The next day he disabled everything attached to Claude and did no work with it, yet consumption rose again.

In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task.

Anthropic told him the account appeared to have been used by an unauthorized-looking third-party service handling activity for other people, and that it could not determine how that access was obtained. The evidence, he said the company told him, was consistent either with credentials being taken without his knowledge or with the account having been connected to an outside service.

A Reddit post about the drain drew 80 comments from other subscribers

He posted his experience on Reddit, and 80 comments later found that other subscribers described the same thing. One said their account was auto-upgraded without consent, their credit card charged, and usage jumped from 0% to 100% without them touching it.

Another watched usage go from 0 to 49% in 12 minutes after a couple of prompts and a web search. A third said the account burned its maximum tokens daily for three days without being used and filed a GitHub report that drew similar accounts.

Two users posted emails in which Anthropic warned that a bad actor was using common infostealer malware to steal Claude login sessions from computers and consume account usage. Anthropic signed those users out, invalidated authorizations, issued some refunds and said the malware did not come from using Claude. Infostealers install on a computer and harvest saved passwords, session data and login credentials.

Anthropic suspended the account and refunded £44.49 of the subscription

He had asked Anthropic for an itemized list of what was consuming his allowance, which account support does not provide even on request. Anthropic suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and refunded £44.49 for the remaining subscription time.

De Swardt did not receive one of those warning emails, and his account was reinstated after about two weeks. The suspension disrupted a business built on agents: he sets up automations for small and mid-size companies, such as loading purchase-order data from emails into accounting software, and relies on agents for his own admin, coding and website work.

He cancelled the $200-per-month subscription in favor of Cursor and its ability to call multiple models, including cheaper open-source ones, which he said work about as well as Claude. He found no evidence that his own computer was compromised and cannot determine how access was gained.

Whether itemized usage arrives

Anthropic has not announced a usage breakdown feature for Claude subscriptions, and De Swardt said the tools to see what consumes tokens are still missing. The scope of the infostealer campaign is also unstated: the warning emails describe a single bad actor without naming how many accounts were drained or over what period.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.