Infostealer malware campaign hijacks Claude login sessions to siphon subscribers' token usage
A wave of Claude (Anthropic) subscribers report unauthorized token consumption on their accounts while inactive. Anthropic confirmed at least one case involved a compromised session key used to mint unauthorized Claude Code OAuth tokens, and separately emailed other affected users warning that a bad actor is using common infostealer malware to steal Claude login sessions from victims' computers and use them to consume account usage. Anthropic responded by signing out affected users, invalidating sessions/authorizations, and issuing some partial refunds; it has not shipped itemized usage tracking that would let users detect or diagnose such theft.
Entities: Anthropic, Claude, Claude Code, Claude Max, Grant De Swardt, Cursor
0 primary
What happened
TechCrunch reports that Claude subscribers are seeing unauthorized token consumption on their accounts while inactive, and that Anthropic has confirmed at least one case where a compromised session key was used to mint unauthorized Claude Code OAuth tokens. Anthropic separately emailed other affected users warning that infostealer malware is stealing Claude login sessions from victims' computers and using them to burn account usage. Reported responses include forced sign-outs, invalidated sessions, and some partial refunds (one user cited £44.49); one named consultant, Grant De Swardt, says his account was suspended for about two weeks, disrupting his business.
Why it matters
This exposes a real gap in how metered AI subscriptions are secured and audited: stolen credentials can be converted directly into consumed inference quota, and without itemized usage logs, victims cannot easily detect, diagnose, or prove theft versus their own usage. That matters most for developers and businesses on usage-based plans (like the $200/month Claude Max), where account suspension or billing disputes can cause direct operational and financial harm, as in the cited two-week suspension. It is also a trust and retention issue: at least one user says he switched to Cursor over it, which is a small but real signal for vendor lock-in and switching costs in the AI coding tool market.
What is noise
There is no official Anthropic public statement or security advisory here; Anthropic's account comes only through forwarded emails to affected users, so the company's official position and its estimate of scale are unverified. The scale of the campaign is not quantified anywhere (unclear if this is dozens of accounts or a wider wave), and "hackers stealing tokens" somewhat overstates the mechanism, which is standard infostealer credential theft repurposed against a new type of asset (metered API/subscription usage) rather than a novel attack on Claude itself.
Watch next
- 01Whether Anthropic issues an official public advisory or status-page statement on this campaign, rather than the current secondhand user-forwarded emails
- 02Whether Anthropic ships itemized/per-session usage tracking for Claude and Claude Code, which would be the actual fix for detection and would validate the story's core claim
- 03Volume signal: growing Reddit/GitHub reports, TechCrunch or other outlet follow-ups with additional named victims, or evidence of scale beyond a handful of individual cases
Coverage
1 storyMore distribution signals
Full feed →- OpenAI ends its contract supplying models to Cursor (Anysphere) after Cursor's acquisition by SpaceX28 Aug 202678
- Google offers Gemini's personalized AI image generation for free to US users29 Jun 202677
- OpenAI launches GPT-6 Astra, claims major capability jump and declares "AGI era"3 Sept 202676
- OpenAI ends its API partnership with Cursor after SpaceX's $60B acquisition of the coding startup3 Sept 202676