Hackers Are Hijacking Claude Accounts to Steal AI Tokens

Cybercriminals are harvesting session keys with infostealer malware to drain expensive Claude AI allowances from unsuspecting subscribers.

By ·

Sep 8, 2026

7 cards · 1 min · tap to begin

From · · · 1 min

Hackers Are Hijacking Claude Accounts to Steal AI Tokens

Cybercriminals are harvesting session keys with infostealer malware to drain expensive Claude AI allowances from unsuspecting subscribers.

In brief

Cybercriminals are harvesting session keys with infostealer malware to drain expensive Claude AI allowances from unsuspecting subscribers. Keep your computer clear of infostealer malware and regularly check your AI token usage, as platforms currently lack itemized usage logs. Originally reported by TechCrunch.

Phantom usage drains subscriber accounts

AI consultant Grant De Swardt noticed his Claude Max token usage climbing rapidly while he was away from work and all automated tasks were paused.

In the clearest controlled interval, it increased from 45% to 55% while I performed no work...

Session keys compromised by third parties

The Anthropic logo is displayed on the screen of a smartphone with the company's branding in the background.

Anthropic confirmed that an unauthorized service obtained a stolen session key to mint Claude Code OAuth tokens and siphon De Swardt's monthly allowance.

Account suspensions disrupt business workflows

To halt the breach, Anthropic invalidated all active session tokens and suspended the account, freezing the automated agents De Swardt relies on to run his business.

Widespread complaints surface online

Dozens of subscribers on Reddit and GitHub reported similar token theft, with usage spiking from zero to 100 percent in minutes without their involvement.

Infostealer malware exposed as culprit

Infostealer malware exposed as culprit

Anthropic warned affected users that common infostealer malware installed on their computers had harvested saved login sessions and login credentials.

We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers...

Missing logs hinder self-defense

Because Anthropic tracks overall consumption without providing an itemized usage breakdown, subscribers have no native tools to audit or detect token theft.

I don’t think there’s any way that these people can protect themselves.

Frustrated users migrate away

Security concerns and slow support response times are driving power users to cancel expensive Claude plans in favor of flexible multi-model coding tools.

The takeaway

Keep your computer clear of infostealer malware and regularly check your AI token usage, as platforms currently lack itemized usage logs.

Read the original on TechCrunch

React

Sign in to react and comment.

Comments (0)

Life is short. Keep it sweet. Respect others' opinions and be kind!

    Recommended next

    More decks on ai and related topics.