
Claude Users Face Token Theft as Hackers Exploit Compromised Sessions
Key takeaways
- Infostealer malware harvested Claude session keys from infected computers to drain paid token allowances covertly.
- Anthropic lacks itemized usage logging visible to customers, allowing theft to remain undetected for weeks or months.
- Multiple users reported 0–100% token drain overnight; Anthropic issued refunds and warned of malware but did not contact all affected parties.
Grant De Swardt, an independent AI consultant in East Sussex, noticed his Claude Max 20x account bleeding tokens on August 4 without any work activity on his end. After disabling all integrations and confirming no tasks were running, token consumption continued climbing—jumping 10 percentage points in one controlled test while De Swardt performed zero work. Anthropic eventually suspended his account and determined a compromised session key had been exploited to mint unauthorized OAuth tokens.
Anthropic later revealed the culprit: infostealer malware harvesting Claude login sessions from infected computers. The company confirmed multiple users faced similar drains, some seeing 100% token depletion overnight. Because Anthropic's support system tracks only total usage, not itemized breakdowns by session, the theft could persist undetected for months. De Swardt's experience, shared on Reddit and GitHub, uncovered dozens of other affected users reporting rapid, unauthorized consumption.
The bigger picture
This incident exposes a structural vulnerability in how subscription AI services handle session security and usage transparency. Anthropic's lack of itemized usage logs—even upon request—means token theft becomes nearly invisible until accounts hit hard limits. Competitors like OpenAI and others offering API-based or subscription tiers should review their own session invalidation policies and whether they surface granular activity data to paying customers. The reliance on individual device hygiene to prevent infostealer compromise shifts security burden back to users.
We're covering this because it's not just a single compromised account—it's a pattern that reveals how emerging AI subscription models handle trust and transparency. De Swardt's frustration with Anthropic's refusal to itemize usage, combined with the widespread Reddit and GitHub reports, signals a real gap between what users expect from a $200/month service and what they're actually getting. Worth watching as AI companies scale.
As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.
You might also like

Slack's AI-Powered Surfaces Turn Chats Into Dynamic Workspaces
Sep 11

Google's AI Summaries Now Dominate Search, Forcing Users to Scroll Past Answers
Aug 29

Nvidia's $12.9B Hugging Face bid signals deepening control over open-source AI
Aug 27

London AI Lab Faraday Beats Claude and GPT-5.5 at Science Tasks Using a 27B-Parameter Model
Aug 23