# Hackers Are Hijacking Claude Accounts to Steal AI Tokens

> Cybercriminals are harvesting session keys with infostealer malware to drain expensive Claude AI allowances from unsuspecting subscribers.
- Title: Hackers Are Hijacking Claude Accounts to Steal AI Tokens
- Summary: Cybercriminals are harvesting session keys with infostealer malware to drain expensive Claude AI allowances from unsuspecting subscribers. Keep your computer…
- Keywords: cybersecurity, anthropic, claude, malware, technology, startups, Hackers, Hijacking, Accounts, Steal, Tokens, TechCrunch
- Source: TechCrunch — https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers
- Author: Julie Bort
- Published: 2026-09-08T21:10:27+00:00
- Read time: 1 min
- Topics: ai, cybersecurity, anthropic, claude, malware, technology, startups
## Phantom usage drains subscriber accounts
AI consultant Grant De Swardt noticed his Claude Max token usage climbing rapidly while he was away from work and all automated tasks were paused.

> In the clearest controlled interval, it increased from 45% to 55% while I performed no work...
## Session keys compromised by third parties
Anthropic confirmed that an unauthorized service obtained a stolen session key to mint Claude Code OAuth tokens and siphon De Swardt's monthly allowance.
## Account suspensions disrupt business workflows
To halt the breach, Anthropic invalidated all active session tokens and suspended the account, freezing the automated agents De Swardt relies on to run his business.
## Widespread complaints surface online
Dozens of subscribers on Reddit and GitHub reported similar token theft, with usage spiking from zero to 100 percent in minutes without their involvement.
## Infostealer malware exposed as culprit
Anthropic warned affected users that common infostealer malware installed on their computers had harvested saved login sessions and login credentials.

> We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers...
## Missing logs hinder self-defense
Because Anthropic tracks overall consumption without providing an itemized usage breakdown, subscribers have no native tools to audit or detect token theft.

> I don’t think there’s any way that these people can protect themselves.
## Frustrated users migrate away
Security concerns and slow support response times are driving power users to cancel expensive Claude plans in favor of flexible multi-model coding tools.
## Key takeaway

Keep your computer clear of infostealer malware and regularly check your AI token usage, as platforms currently lack itemized usage logs.