SDSignal Desk

Hackers are stealing Claude tokens from subscribers

Sep 8, 2026, 2:10 PM · TechCrunch

Image: TechCrunch

Infostealer theft of Claude sessions turns expensive Max subscriptions into a silent shared compute pool — and Anthropic's opacity is becoming a churn engine.

Why it matters

TechCrunch reports that independent AI consultant Grant De Swardt watched his Claude Max 20x usage climb on a day he was not working. The next day, with attachments disabled and no local Claude Code task running, usage still rose — including a controlled interval from 45% to 55%. Anthropic suspended the paid account, invalidated sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 on his $200-per-month plan.

Anthropic later told him a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens, and that the account appeared to have been used by an unauthorized-looking third-party service. The company could not determine how access was obtained. De Swardt says he found no malware evidence and still lacks an itemized usage trail.

He is not alone. Reddit and GitHub threads describe similar unexplained burns — including accounts Anthropic itself emailed to warn that common infostealer malware was stealing Claude login sessions. Those users were signed out, authorizations invalidated, and some refunded. De Swardt did not get that proactive email. After roughly two weeks reinstated, he cancelled for Cursor and multi-model options.

The Signal Desk read

Signal Desk's read: this is subscription fraud plus product-trust failure, not a niche support anecdote. High-tier Claude seats are valuable enough that stealing a session is economically rational. When support tracks totals but not itemized consumption, theft can run for long stretches as "mysterious usage." That design choice is now a security and retention problem.

Anthropic deserves partial credit for detecting some victims and sending plain-language warnings about infostealers. It also deserves blame for the gaps De Swardt hit: no itemized burn-down on request, no clear user-side way to see which tokens or OAuth grants are active, and a suspension that wrecked a sole proprietor's agent-dependent workflow before restoration. Power users who wire Claude into client ops will not tolerate "trust us, we invalidated sessions" as the entire incident response.

The competitive implication is immediate. Cursor's multi-model pitch — including cheaper open options — wins when Claude feels like a black box meter someone else can drain. De Swardt's line that other models are "not that much different or better" is the churn quote Anthropic should fear: once quality parity is close enough, observability and account integrity decide loyalty.

Expect more silent token farming until Anthropic ships per-session and per-integration metering, forced re-auth on anomalous burn rates, and clearer malware guidance without waiting for victims to file tickets. Session-stealing malware is not Claude-specific; treating it as a Claude billing mystery is a self-inflicted wound.

Context

Infostealers typically harvest saved passwords and browser session cookies from infected machines via malicious downloads or ads. Anthropic told warned users the malware did not come from Claude itself. De Swardt's reinstatement after about two weeks ended the immediate outage but not the transparency complaint that drove cancellation.

Who feels it

Claude Max / power subscribers
Need anomaly alerts, itemized usage, and a live inventory of sessions and Claude Code OAuth tokens — not just refunds after the fact.
Anthropic
Risks high-ARPU churn to multi-model IDEs unless account integrity tooling matches the price of Max tiers.
SMB agent consultants
Single-vendor agent stacks create business continuity risk when a compromised seat triggers suspension.

What to watch

  1. Whether Anthropic ships itemized usage and session/OAuth visibility after declining to comment on misuse identification.
  2. Volume of similar reports and proactive Anthropic warning emails over the next few weeks.
  3. Churn toward Cursor and other multi-model tools among Max-tier users citing metering opacity.

Read the original

Continue at the source.

TechCrunch

Companies: Anthropic